Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

0Xmagic0

#32029of 57,305
8.8Total CVSS
Vulnerabilities · 1
PT-2026-96924
8.8
2026-09-22
Atlassian · Mcp-Attlasian · CVE-2026-77243
**Name of the Vulnerable Software and Affected Versions** MCP Atlassian versions prior to 0.22.0 **Description** An authorization bypass exists where the `ENABLED TOOLS` and `TOOLSETS` filters are only enforced during the `tools/list` request and are not re-verified when a `tools/call` request is dispatched. This allows a client who knows the name of a hidden tool to directly invoke excluded read, write, or delete operations, bypassing least-privilege restrictions. The issue occurs because the ` call tool mcp` function resolves tools from the full unfiltered registry rather than the filtered list. This impact is most significant in multi-user HTTP-transport deployments where these filters serve as a trust boundary between clients. **Recommendations** Update MCP Atlassian to version 0.22.0.