Junglewise Threat Intelligence

CVE-2026-77256: MCP Atlassian insecure file permissions in OAuth token storage

CVE-2026-77256 · Severity: info · Published 2026-09-22

Technologies: Sooperset Mcp-Atlassian. Vendors: Sooperset.

Executive brief

MCP Atlassian is a Model Context Protocol server that connects AI models to Atlassian products like Jira and Confluence. Before version 0.22.0, OAuth refresh and access tokens are saved to a backup file with permissions inherited from the process umask, potentially allowing other local users on the system to read the file and gain unauthorized access to Atlassian accounts.

Technical details

The vulnerability exists in OAuthConfig._save_tokens_to_file, which writes plaintext OAuth refresh and access tokens to a file with default permissions based on the process umask. Under permissive umask configurations, other local users can read this backup file and extract the refresh token to maintain Atlassian access. The fix in version 0.22.0 restricts file permissions to prevent unauthorized local access.

Affected products

  • sooperset MCP Atlassian prior to 0.22.0

Timeline

  • 2026-09-22: disclosed
  • 2026-07-10: patched: Fix merged in version 0.22.0

References

Related threats