PT-2026-96924 · Atlassian · Mcp-Attlasian

·

CVE-2026-77243

·

Published

2026-09-22

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description An authorization bypass exists where the ENABLED TOOLS and TOOLSETS filters are only enforced during the tools/list request and are not re-verified when a tools/call request is dispatched. This allows a client who knows the name of a hidden tool to directly invoke excluded read, write, or delete operations, bypassing least-privilege restrictions. The issue occurs because the call tool mcp function resolves tools from the full unfiltered registry rather than the filtered list. This impact is most significant in multi-user HTTP-transport deployments where these filters serve as a trust boundary between clients.
Recommendations Update MCP Atlassian to version 0.22.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77243
GHSA-3R68-HF9H-887V

Affected Products

Mcp-Attlasian