Impact
In the MCP Atlassian server, the lists ENABLED_TOOLS and TOOLSETS are applied only when tools are first enumerated but are not re‑verified when a call to a tool is made. An attacker who knows the name of a hidden tool can call that tool directly, executing read, write, or delete operations that the operator had intended to block. This flaw allows an attacker to bypass the least‑privilege policy that the operator configured, effectively granting unauthorized operations against the underlying Atlassian product data.
Affected Systems
The issue affects the sooperset:mcp-atlassian product in all releases prior to version 0.22.0. The vulnerability is fixed starting with that release. The affected environment is a Model Context Protocol server used by Atlassian Confluence and Jira.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. Because the EPSS score is not available, the exact likelihood cannot be quantified, but the flaw is exploitable by any entity that can send a request to the MCP server after discovering a hidden tool name. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw remotely over the network without needing privileged access to the server, making it a significant threat for deployments that expose the MCP endpoint without proper access controls.
OpenCVE Enrichment
Github GHSA