Impact
The vulnerability permits any network caller to send HTTP MCP requests without a user identity. These requests are processed by tool handlers that utilize a globally configured Jira or Confluence credential, allowing the attacker to perform any action authorized for the operator account, such as reading, modifying, or deleting data. This scenario represents a privilege‑escalation risk.
Affected Systems
The issue affects deployments of the MCP Atlassian server provided by Sooperset, version 0.21.x and earlier. The product is a Model Context Protocol server that exposes an HTTP endpoint for interacting with Confluence and Jira. No other vendors are listed, so the scope is limited to this specific Sooperset product.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity. While the EPSS score is not available, the lack of a KEV listing does not negate the exploitation potential. The attacker can exploit the path remotely from any network location that can reach the MCP endpoint by sending unauthenticated HTTP requests; this is inferred from the description of the vulnerability. After patching, the path is closed, but until then the vulnerability remains fully exploitable for unauthenticated users.
OpenCVE Enrichment