Executive brief
MCP Atlassian is a server that integrates Atlassian products (Confluence and Jira) with AI assistants via the Model Context Protocol. An attacker can bypass administrator-configured restrictions on which projects or spaces are searchable, allowing them to access projects or spaces outside the intended boundary if their supplied credentials have access to them. This could lead to unauthorized data exposure or information disclosure.
Technical details
The vulnerability is an authorization bypass in versions prior to 0.22.0 where caller-supplied projects_filter and spaces_filter arguments replace administrator-configured allowlists (JIRA_PROJECTS_FILTER, CONFLUENCE_SPACES_FILTER), and caller-provided project or space clauses can suppress configured restrictions. The issue exists in SearchMixin.search_issues and SearchMixin.search code paths and affects any caller who can invoke the vulnerable search entry points with network access to the MCP server; the fix applies hard boundary logic where configured filters always AND into queries and tool arguments can only narrow, never replace, the allowlist.
Affected products
- sooperset mcp-atlassian prior to 0.22.0
Timeline
- 2026-09-22: disclosed
- 2026-07-10: patched