← Back to search

CVE-2026-77243

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows a client to invoke hidden tools despite configured least-privilege restrictions, leading to potential unauthorized access to read, write, or delete operations.
Exploitability
Exploitation is moderately hard as it requires knowledge of hidden tool names, but once obtained, the attack can bypass security controls.
Blast radius
If exploited, this could lead to significant data breaches or system compromise, affecting Confluence and Jira users.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to MCP Atlassian 0.22.0 or later.
auth-bypasswebatlassian

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatched. A client that knows a hidden tool name can directly invoke excluded read, write, or delete tools despite the operator's configured least-privilege restrictions. The advisory traces the vulnerable input and processing flow through ENABLED_TOOLS, TOOLSETS, tools/list, tools/call, and _call_tool_mcp, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-862

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.