logo

Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products

ID: fdaf0be6-c5d6-5190-83d6-3b7f639eb540

STIX ID: report--fdaf0be6-c5d6-5190-83d6-3b7f639eb540

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-22

...
...

The Secure Login (2FA) plugin for Atlassian products contains a broken access control flaw that enables attackers with valid user credentials to bypass multi-factor authentication by altering the HTTP User-Agent header. Successful exploitation can provide unauthorized access to administrative settings and permit disabling of 2FA across affected installations; the vendor has released a patch and immediate remediation is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.