Back

HIGH

MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass

Published Sep 22, 2026

Description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 22, 2026
Updated Sep 22, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 22, 2026
NVD
Status Analyzed
Modified Sep 29, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Sep 22, 2026
Updated Sep 22, 2026
Exploited since n/a
EUVD-2026-84626 GHSA-3R68-HF9H-887V