
『an attacker to bypass the Two-Factor Authentication process with any account by using a specific user agent in their HTTP requests.』😨 CVE-2026-12225 Broken Access Control in syracom AG Secure Login (2FA) for Atlassian Jira / Confluence / Bitbucket https://sec-consult.com/vulnerability-lab/advisory/broken-access-control-in-syracom-ag-secure-login-2fa-for-atlassian-jira-confluence-bitbucket/
Post summary
The post announces a discovered vulnerability (CVE‑2026‑12225) allowing attackers to bypass Two‑Factor Authentication by sending requests with a specific user agent in syracom AG Secure Login for Atlassian products.
