Executive brief
A vulnerability in the syracom AG Secure Login plugin for Atlassian products allows users to bypass two-factor authentication (2FA). By mimicking a mobile device through a modified web browser setting, an attacker with a stolen password can gain full access to Jira, Confluence, or Bitbucket accounts without the required secondary security code. This could lead to unauthorized access to sensitive corporate data or the ability for an attacker to disable security settings if an administrative account is compromised.
Technical details
An authentication bypass vulnerability (CWE-288) exists in syracom AG Secure Login (2FA) versions 3.4.0.x for Atlassian Jira, Confluence, and Bitbucket. The plugin fails to enforce 2FA checks when it encounters specific User-Agent strings, such as 'AtlassianMobileApp' or 'JIRA', which are intended to identify mobile applications. An attacker with valid primary credentials (username and password) can exploit this by sending HTTP requests with a crafted User-Agent header to bypass the MFA requirement entirely. Successful exploitation grants the attacker the privileges of the compromised user, potentially allowing for administrative changes or the deactivation of the 2FA plugin if the account has sufficient permissions. The issue is resolved in version 3.5.0.0.
Affected products
- syracom AG Secure Login (2FA) for Jira 3.4.0.x
- syracom AG Secure Login (2FA) for Confluence 3.4.0.x
- syracom AG Secure Login (2FA) for Bitbucket 3.4.0.0
Timeline
- 2026-02-27: other: Vulnerability discovered by SEC Consult
- 2026-03-10: other: Vendor contacted
- 2026-05-11: patched: Vendor releases version 3.5.0.0 and advisory
- 2026-06-16: disclosed: SEC Consult and NVD publish advisory
References
- https://marketplace.atlassian.com/apps/1214491/secure-login-2fa-for-confluence
- https://r.sec-consult.com/syracom
- https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/4193255427/2026-05-11+-+Secure+Login+security+advisory+-+Broken+Access+Control
- https://syracom-bee.atlassian.net/wiki/spaces/SL/pages/4230217729/Mobile+app+login+does+not+work+with+Secure+Login