CVE-2026-77256
6.5 MEDIUMpublic exploit availablePublished 2026-09-22 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other local users can read the backup and retain Atlassian access through the refresh token. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens_to_file, refresh_token, access_token, and umask, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-732
Vendors
mcp-atlassian
Products
mcp atlassian
Public exploit & PoC references
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460[Patch]
- https://github.com/sooperset/mcp-atlassian/pull/1448[Issue Tracking, Patch]
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0[Release Notes]
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-76pr-5669-3xf5[Mitigation, Vendor Advisory]
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-76pr-5669-3xf5[Mitigation, Vendor Advisory]
All references
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460
- https://github.com/sooperset/mcp-atlassian/pull/1448
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-76pr-5669-3xf5
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-76pr-5669-3xf5
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-13673
- MEDIUMCVE-2026-15952
- CRITICALCVE-2026-39353PoC
- HIGHCVE-2026-49811
- UNSCOREDCVE-2026-68490
- MEDIUMCVE-2026-76104
- MEDIUMCVE-2026-77268PoC
- HIGHCVE-2026-82164
Related by shared AI tags and CWE weakness class. Browse the full archive.