chiprook
← Security
SecurityOctober 5, 2026, 23:40

MCP Atlassian Falls Back to Operator Credentials Without Verified Identity

MCP Atlassian server (CVE-2026-77244) executes HTTP requests with no verified identity using the operator's global credentials, granting full Jira and Confluence access. The flaw is fixed in version 0.22.0, which also patches a file-path issue CVE-2026-73496 (7.7).

MCP Atlassian Falls Back to Operator Credentials Without Verified Identity
#Atlassian#Jira#Confluence
Read next
Software

Atlassian opens Jira Automation Rules management API

Security

Proof Launches Verifiable Digital Credential for Banking, Reusable Identity and AI Agents

Security

ZoomEye: 1.8M Confluence matches depend on which fingerprint you use

Security

Google Now Asks Users for Video Selfies to Verify Identities