PT-2026-96926 · Unknown · Mcp-Attlasian

·

CVE-2026-77251

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description Three distinct issues allow attacker-controlled queries to access content from forbidden projects or spaces, bypassing the restrictions set by the JIRA PROJECTS FILTER and CONFLUENCE SPACES FILTER environment variables. These filters are intended to limit MCP clients, such as prompt-injected LLM agents, to a specific subset of the workspace.
The issues occur in the following areas:
  • In the jira search function, a substring check is bypassed when a user provides a JQL query containing project = <forbidden-project>, allowing access to projects not in the allowlist.
  • In the confluence search function, the substring check for space = is case-sensitive, meaning a query using SPACE = <forbidden-space> bypasses the filter.
  • The get board issues() and get agile boards() functions completely omit the projects filter enforcement, allowing the enumeration of boards and issues across the entire workspace.
These flaws are exploitable when the operator's credentials have broader access permissions than the intended allowlist.
Recommendations Update MCP Atlassian to version 0.22.0. As a temporary mitigation, restrict the permissions of the Personal Access Token (PAT) used by the operator to only the projects and spaces that should be accessible.

Exploit

Fix

Incorrect Authorization

Incomplete List of Disallowed Inputs

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77251
GHSA-W66G-J6C4-HCFC

Affected Products

Mcp-Attlasian