Broken Access Control in syracom AG Secure Login (2FA) for Atlassian
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket was vulnerable to a flaw that allowed attackers to bypass the implemented multi-factor authentication (MFA). Successful exploitation allowed an attacker with access to valid user credentials to completely bypass MFA protection. CVE-2026-12225


