A security vulnerability has been identified in MCP Atlassian, specifically affecting versions prior to 0.22.0. When requests are made over HTTP without a verified identity, the system defaults to using the operator's credentials for Jira and Confluence. This fallback mechanism allows unauthorized access to these tools with the operator's privileges. Several other related vulnerabilities in MCP and its tools have also been reported, some of which have been added to the Known Exploited Vulnerabilities catalog. AI
IMPACT Exposes AI assistants integrated with Jira and Confluence to unauthorized access, necessitating immediate security upgrades.
RANK_REASON Security vulnerability disclosure for a specific software tool.
- Azure Resource Manager
- Confluence
- CVE-2026-53957
- CVE-2026-54549
- CVE-2026-57441
- CVE-2026-57442
- CVE-2026-58201
- CVE-2026-59822
- CVE-2026-61560
- CVE-2026-73496
- CVE-2026-77244
- HTTP
- Jira
- Known Exploited Vulnerabilities Catalog
- LiteLLM
- MCP Atlassian
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →