CVE-2026-77256
MCP Atlassian: OAuth refresh-token backup file is world-readable under default Unix umask
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the process umask. Under common or permissive configurations, other local users can read the backup and retain Atlassian access through the refresh token. The advisory traces the vulnerable input and processing flow through OAuthConfig._save_tokens_to_file, refresh_token, access_token, and umask, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.
| CWE | CWE-732 |
| Vendor | sooperset |
| Product | mcp-atlassian |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Get instant alerts for sooperset mcp-atlassian
Be the first to know when new unknown vulnerabilities affecting sooperset mcp-atlassian are published โ delivered to Slack, Telegram or Discord.