MCP Atlassian Falls Back to Operator Credentials Without Verified Identity
MCP Atlassian server (CVE-2026-77244) executes HTTP requests with no verified identity using the operator's global credentials, granting full Jira and Confluence access. The flaw is fixed in version 0.22.0, which also patches a file-path issue CVE-2026-73496 (7.7).
- CVE-2026-77244: unauthenticated HTTP calls run as the operator's global credentials
- Fixed in 0.22.0; all earlier releases are affected
- 0.22.0 also closes CVE-2026-73496 (7.7) — attachment upload outside the intended directory
- Part of a series of MCP flaws: CVE-2026-57441 (8.4), CVE-2026-58201 (8.7)
Read next
Software