logo

Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products

ID: 773f27bb-e29b-598e-9963-f865f7686660

STIX ID: report--773f27bb-e29b-598e-9963-f865f7686660

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-20

...
...

A critical broken access control flaw in the Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket allows attackers who possess valid user credentials to bypass MFA by spoofing the HTTP user agent. Successful exploitation can grant unauthorized access to administrative settings and the ability to disable 2FA for all user roles; the vendor has released a patch and immediate application is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.