Atlassian · Mcp-Attlasian · CVE-2026-77243
**Name of the Vulnerable Software and Affected Versions**
MCP Atlassian versions prior to 0.22.0
**Description**
An authorization bypass exists where the `ENABLED TOOLS` and `TOOLSETS` filters are only enforced during the `tools/list` request and are not re-verified when a `tools/call` request is dispatched. This allows a client who knows the name of a hidden tool to directly invoke excluded read, write, or delete operations, bypassing least-privilege restrictions. The issue occurs because the ` call tool mcp` function resolves tools from the full unfiltered registry rather than the filtered list. This impact is most significant in multi-user HTTP-transport deployments where these filters serve as a trust boundary between clients.
**Recommendations**
Update MCP Atlassian to version 0.22.0.