Skip to main content

Broken Access Control in syracom AG Secure Login (2FA) for Atlassian

The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket was vulnerable to a flaw that allowed attackers to bypass the implemented multi-factor authentication (MFA). Successful exploitation allowed an attacker with access to valid user credentials to completely bypass MFA protection. CVE-2026-12225

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 17th Edition

  • Magazine

Digital security magazine 18th Edition