MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
Published Sep 22, 2026
8.8
HIGHCVSS 3.1
EPSS 0.32%
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
Affected products
-
- Version < 0.22.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Sooperset | Mcp-Atlassian | n/a |
|
- < 0.22.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84626 Advisory
- https://github.com/advisories/GHSA-3r68-hf9h-887v Advisory
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/pull/1448 x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-3r68-hf9h-887v exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-77243
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84626 | Advisory | |
| https://github.com/advisories/GHSA-3r68-hf9h-887v | Advisory | |
| https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 | x_refsource_MISC | |
| https://github.com/sooperset/mcp-atlassian/pull/1448 | x_refsource_MISC | |
| https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 | x_refsource_MISC | |
| https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-3r68-hf9h-887v | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-77243 |
Change history (0)
No recorded changes yet.