CVE-2026-77254: MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials

Published Sep 22, 2026
·
Updated

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform operations with the operator account's permissions unless the deployment has an independent authentication boundary. The advisory traces the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, getfetcher, and global credentials, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Affected Software

1 affected component
MCP Atlassian MCP Atlassian<0.22.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MCP Atlassian to a version that resolves this vulnerability.

    Fixed in 0.22.0
  2. Compensating control

    Deploy an independent authentication boundary for the HTTP MCP endpoint so unauthenticated network callers cannot use the operator account's globally configured Jira or Confluence credentials.

Event History

Sep 22, 2026
CVE Published
via MITRE·06:11 PM
Data Sourced
via MITRE·06:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated use of the configured Atlassian account?

Deployments running a version prior to 0.22.0 are exposed when their HTTP MCP endpoint is reachable by a network caller and no independent authentication boundary prevents unauthenticated requests from reaching it. The issue affects both Jira and Confluence operations when global credentials are configured.

2

What does an attacker need to exploit this issue?

An attacker needs network access to the HTTP MCP endpoint. No authentication, user identity, or user interaction is required if the endpoint lacks an independent authentication boundary.

3

What access could an attacker obtain through a vulnerable endpoint?

Unauthenticated requests can reach MCP tool handlers that use the globally configured Jira or Confluence credentials. An attacker can therefore perform operations with the permissions of the operator account associated with those credentials.

4

What should be done if upgrading cannot happen immediately?

Place an independent authentication boundary in front of the HTTP MCP endpoint so unauthenticated network callers cannot reach it. Restricting network access to trusted callers also reduces exposure.

5

How can an administrator determine whether an instance is affected?

An instance is affected if it runs MCP Atlassian before version 0.22.0, has globally configured Jira or Confluence credentials, and permits unauthenticated requests to reach the HTTP MCP endpoint. The relevant processing path includes streamable-http, UserTokenMiddleware, _get_fetcher, and use of global credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203