CVE-2026-77268
📛 CVE Title
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
Description
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory traces the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitHub_M
- CVSS severity
- MEDIUM
- CVSS score
- 5.5 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N- Effective score
- 5.5 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-732 - Reserved
- 2026-08-20
- Published
- 2026-09-22 18:44 UTC
- Last updated
- 2026-09-22 18:44 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/77xxx/CVE-2026-77268.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 19:16:50 UTC
- NVD last modified
- 2026-09-22 19:16:50 UTC
- NVD CVSS v3.1
- 5.5 / 10 MEDIUM source: security-advisories@github.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 3.6 / 10
NVD / KEV / EPSS data refreshed 2026-09-23 02:41 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84757 - Assigner
- GitHub_M
- Published
- Sep 22, 2026, 6:44:46 PM
- Updated
- Sep 22, 2026, 6:44:46 PM
- EUVD base score (CVSS 3.1)
-
5.5 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EUVD-reported EPSS
- 0.0000
- Vendors
- sooperset
- Products
-
mcp-atlassian (< 0.22.0)
- Aliases
-
GHSA-4596-2p6p-28cv
ENISA description: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory traces the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
EUVD references (4)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| sooperset | mcp-atlassian |
< 0.22.0 (affected)
|
— |
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-4596-2p6p-28cv x_refsource_CONFIRM
- https://github.com/sooperset/mcp-atlassian/pull/1448 x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 x_refsource_MISC
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 x_refsource_MISC
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460 security-advisories@github.com
- https://github.com/sooperset/mcp-atlassian/pull/1448 security-advisories@github.com
- https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0 security-advisories@github.com
- https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-4596-2p6p-28cv security-advisories@github.com
Remediations (10)
-
web:blog.qualys.com
Executive Summary ShieldBreak ( CVE - 2026 -69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026 , and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across ...
2026-09-23 15:44 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-09-23 15:44 UTC -
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-09-23 15:44 UTC -
web:playvalorant.com
VALORANT's big update is here. TL;DR: The big one is here. A new home and lobby experience, Agent Mastery system, Gauntlet: Glitched, Practice Range in Queue, The Warden, Competitive Updates, and more are ALL LAUNCHING TODAY! Sup, gamers?! It's Kenny here to break down our biggest patch of the year—ok, maybe it's the biggest patch of the last few years. Maybe ever? Idk. Anyway, sit ...
2026-09-23 15:44 UTC -
web:survivetheark.com
Changelog / Patch Notes The latest changes that have been made and are upcoming to ARK.
2026-09-23 15:44 UTC -
web:www.onixs.biz
FIX 4.2 - FIX Dictionary - Onix Solutions Messages by MsgType | Messages by Name | Fields by Tag | Fields by Name | Home FIX 4.2
2026-09-23 15:44 UTC -
web:www.onixs.biz
FIX 4.4 Messages by Category Appendix 6-A Appendix 6-B Appendix 6-C Appendix 6-D Appendix 6-E Appendix 6-F Appendix 6-G Appendix 6-H Appendix D Appendix E Appendix F Glossary Component Blocks StandardHeader StandardTrailer CommissionData DiscretionInstructions FinancingDetails Instrument InstrumentExtension InstrumentLeg LegBenchmarkCurveData ...
2026-09-23 15:44 UTC -
web:www.oracle.com
Oracle Critical Security Patch Update Advisory - August 2026 Description. A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, mor
2026-09-23 15:44 UTC -
web:www.romhacking.net
An online web-based ROM patcher. Supported formats: IPS, BPS, UPS, APS, RUP, PPF and xdelta.
2026-09-23 15:44 UTC -
web:www.stalker2.com
Patch notes A comprehensive archive of changes, tweaks, and fixes introduced with every patch and major update of S.T.A.L.K.E.R. 2: Heart of Chornobyl. Your feedback helps us refine the Zone — if you encounter an anomaly that doesn't belong there, report it via the Technical Support Hub.
2026-09-23 15:44 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-77268.json.
{
"containers": {
"cna": {
"affected": [
{
"product": "mcp-atlassian",
"vendor": "sooperset",
"versions": [
{
"status": "affected",
"version": "< 0.22.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission bits can read access and refresh tokens and reuse the associated Atlassian session. The advisory traces the vulnerable input and processing flow through ~/.mcp-atlassian, oauth-<client_id>.json, access_token, and refresh_token, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-732",
"description": "CWE-732: Incorrect Permission Assignment for Critical Resource",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T18:44:46.039Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-4596-2p6p-28cv",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-4596-2p6p-28cv"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/pull/1448",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/pull/1448"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460"
},
{
"name": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0"
}
],
"source": {
"advisory": "GHSA-4596-2p6p-28cv",
"discovery": "UNKNOWN"
},
"title": "MCP Atlassian: Insecure File Permissions on OAuth Token Storage"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-77268",
"datePublished": "2026-09-22T18:44:46.039Z",
"dateReserved": "2026-08-20T19:14:21.330Z",
"dateUpdated": "2026-09-22T18:44:46.039Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}