CVE-2026-77244
10.0sooperset · mcp-atlassian
An authentication bypass in sooperset mcp-atlassian allows unauthenticated network clients to perform unauthorized read and write operations on linked Atlassian Jira and Confluence instances.
Executive summary
A critical authentication vulnerability in sooperset mcp-atlassian allows unauthenticated remote attackers to execute arbitrary operations as the configured operator.
Vulnerability
This is an improper authentication and missing authorization flaw where the HTTP transport fails to verify user identity. An unauthenticated attacker can interact with the server, causing it to fall back to the operator's global credentials when communicating with downstream Atlassian services.
Business impact
The ability for an unauthenticated attacker to perform read and write operations on internal Jira and Confluence environments represents a severe security risk. This could lead to unauthorized data exfiltration, the modification of project documentation, or the manipulation of sensitive task management workflows. Given the CVSS score of 10.0, this vulnerability poses an existential threat to the integrity and confidentiality of the organization's Atlassian data.
Remediation
Immediate Action: Update the sooperset mcp-atlassian package to version 0.22.0 or later immediately to enforce proper authentication.
Proactive Monitoring: Review access logs for the MCP endpoint to identify requests originating from unauthorized or unexpected network segments.
Compensating Controls: Restrict network access to the MCP endpoint using firewall rules or a reverse proxy requiring mutual TLS (mTLS) or platform-native authentication until the update can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is critical due to the combination of unauthenticated access and the ability to perform write operations against core business tools. Organizations must prioritize patching this component to version 0.22.0 immediately. If the service cannot be updated, it must be isolated from the network to prevent unauthorized access to sensitive Atlassian data.
More sooperset CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section