CVE-2026-77251

8.3

sooperset · mcp-atlassian

The mcp-atlassian server fails to enforce project and space filters for Jira and Confluence, allowing authenticated users to access data outside their intended scope.

Executive summary

The mcp-atlassian server contains an authorization bypass vulnerability that permits authenticated users to access restricted Jira and Confluence data, posing a significant risk of unauthorized information disclosure.

Vulnerability

This is an authorization enforcement vulnerability where the server fails to properly validate project and space filters in search and board APIs. An authenticated user can bypass defined filters to access sensitive information that should be restricted based on their assigned permissions.

Business impact

Successful exploitation allows an authenticated user to gain unauthorized access to Jira issues, boards, or Confluence pages that are intended to be hidden from them. With a CVSS score of 8.3, this high-severity flaw could lead to the exposure of sensitive corporate data and internal project workflows. This breach of confidentiality may result in significant reputational damage and the compromise of proprietary intellectual property.

Remediation

Immediate Action: Update the mcp-atlassian package to version 0.22.0 or later to resolve the incorrect authorization logic.

Proactive Monitoring: Review access logs for unusual patterns of API requests originating from authenticated users, specifically targeting Jira search and board retrieval endpoints.

Compensating Controls: Ensure that the underlying Atlassian service accounts possess the principle of least privilege, limiting their access to only the projects and spaces strictly required for their operational function.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high impact on data confidentiality and the availability of a confirmed vendor patch, organizations using mcp-atlassian must prioritize updating to version 0.22.0. Failure to patch allows authenticated users to potentially browse restricted project data, undermining the security posture of integrated Atlassian environments. Prompt application of the update is the only effective way to ensure that project-level access controls are correctly enforced.

More sooperset CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources