MCP Atlassian Falls Back to Operator Credentials When No Identity Is Present
Opening
The MCP Atlassian server gives an AI assistant a set of tools for Jira and Confluence. To use them it holds credentials for both systems. CVE-2026-77244 concerns which credentials it uses when a request arrives over HTTP without a verified identity: the operator's.
The behaviour is the shipped default. A deployment that never configured authentication on the endpoint is not saved by some other mistake being absent, because the fallback is what the code does when the check does not run.
Technical context
An MCP server is a process that exposes tools to an assistant. The Atlassian server supports two transports. Over stdio the assistant spawns the process locally, so there is a parent process and a user context to trust. Over HTTP the server listens on a socket, which makes anyone who can reach that socket a client.
The defect sits in the HTTP path. When the server cannot establish the caller's identity, it falls back to the operator's global credentials instead of refusing the call. A caller who reaches the MCP endpoint therefore acts as the operator against Jira and Confluence, with whatever reach that account has.
The fix boundary is version 0.22.0. Releases before 0.22.0 are affected. The same release also closes a file-path flaw, CVE-2026-73496, scored 7.7, where the attachment upload tool accepted a path outside the directory it was meant to work in.
This is a pattern rather than one bug. Reporting through September 2026 collected a run of MCP and tool-endpoint flaws in which the default configuration was the vulnerability. CVE-2026-61560 allowed a file_path parameter to read /proc/self/environ. CVE-2026-57441, scored 8.4, defeated a path filter on case-insensitive filesystems because .git and .obsidian had variants that passed both the allow check and the listing check; CVE-2026-57442, scored 6.9, bypassed a deny list that was anchored at the root, so a nested .git path segment slipped past it. CVE-2026-54549, scored 8.3, handed an attacker-controlled image URL to an HTTP client that followed redirects without validating scheme, host or resolved address. CVE-2026-53957, scored 7.7, exposed host and proxy options as tool parameters the model could set. CVE-2026-58201, scored 8.7, joined a user-controlled path onto an Azure Resource Manager base URL, which changed how the authority was parsed and sent a bearer token to a host the operator never chose.
The same class reached the Known Exploited Vulnerabilities catalog earlier in 2026. LiteLLM's CVE-2026-59822 let an arbitrary bearer token open an authenticated MCP session over a Streamable HTTP endpoint that was supposed to validate the token.
Explanation or walkthrough
The mechanism in CVE-2026-77244 is the ordering of a fallback. Authentication is supposed to decide who the caller is. When the HTTP transport has no verified identity, the code needs a principal to pass to the Jira and Confluence clients. Instead of failing the request, it supplies the one principal it always has available, which is the operator the server was configured with.
From the endpoint's point of view there is nothing unusual to see. The call is well formed, the tools are the tools the server publishes, and the audit trail on the Atlassian side records activity by a legitimate account. Access control on the MCP endpoint is the only control that was supposed to matter, and it was optional in the default deployment.
Defensive implications
Upgrade to 0.22.0 or later. Then check whether the endpoint was reachable before the upgrade, because a server that accepted calls without identity accepted them as its operator, and that account's Jira and Confluence history will show the results.
Do not expose MCP endpoints to networks that do not need them. The transport is a control surface, and a control surface with an optional identity check belongs on a management network or behind an authenticating proxy.
Audit what the operator credential can do rather than what the tool list suggests. The tool list describes intended actions; the credential determines actual reach, including projects, spaces and administrative endpoints the tools do not mention.
Treat tool inputs as untrusted. Several of the September findings turn a parameter into a filesystem path, a URL or a network destination. Validation belongs on the assumption that the caller is not the trusted operator, because on an HTTP transport it is not.
References
- MCP Atlassian project, GitHub: https://github.com/sooperset/mcp-atlassian
- Daily security intelligence report, 2026-09-25: https://blog.csdn.net/weixin_45635831/article/details/166643236
- FreeBuf analysis of MCP default-configuration flaws: https://www.freebuf.com/articles/ai-security/501022.html
- Bifrost-related MCP and gateway exposure measurements, ZoomEye: https://www.zoomeye.org/
Top comments (0)