PT-2026-96953 · Unknown · Mcp-Attlasian

·

CVE-2026-77268

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MCP Atlassian versions prior to 0.22.0
Description The OAuth fallback token directory and JSON files are created without restrictive owner-only permissions, typically resulting in world-readable files (mode 0644 on Linux) and directories (mode 0755). This allows local users or processes on shared systems to read sensitive credentials, including access token, refresh token, cloud id, and base url, from the ~/.mcp-atlassian directory and oauth-<client id>.json files. An attacker can use these tokens to impersonate the victim and gain unauthorized persistent access to Jira and Confluence data via the Atlassian API. The issue occurs within the save tokens to file() function in src/mcp atlassian/utils/oauth.py when the software falls back to file storage because the system keyring is unavailable.
Recommendations Update to version 0.22.0. As a temporary mitigation, restrict access to the ~/.mcp-atlassian directory and any oauth-*.json files to the owner only by applying restrictive filesystem permissions (e.g., chmod 700 for the directory and chmod 600 for the files).

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77268
GHSA-4596-2P6P-28CV

Affected Products

Mcp-Attlasian