Answer in brief
CVE-2026-12225 records a High severity (CVSS 8.7) vulnerability in syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent. The current sources do not mark it as known exploited. The current feed maps syracom AG/Secure Login (2FA) for Bitbucket (generic), syracom AG/Secure Login (2FA) for Confluence (generic), syracom AG/Secure Login (2FA) for Jira (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-12225 records a High severity (CVSS 8.7) vulnerability in syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent. The current sources do not mark it as known exploited. The current feed maps syracom AG/Secure Login (2FA) for Bitbucket (generic), syracom AG/Secure Login (2FA) for Confluence (generic), syracom AG/Secure Login (2FA) for Jira (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps syracom AG/Secure Login (2FA) for Bitbucket (generic), syracom AG/Secure Login (2FA) for Confluence (generic), syracom AG/Secure Login (2FA) for Jira (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| syracom AG/Secure Login (2FA) for Bitbucketgeneric | 3.4.0.0 | Not reported |
| syracom AG/Secure Login (2FA) for Confluencegeneric | >=3.4.0.0 <3.5.0.0 | 3.5.0.0 |
| syracom AG/Secure Login (2FA) for Jirageneric | >=3.4.0.0 <3.5.0.0 | 3.5.0.0 |
Published upstream
Jun 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 21, 2026
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings such as AtlassianMobileApp or JIRA. When such a User-Agent is present, the plugin does not enforce the configured 2FA checks for protected web resources. Successful exploitation allows the attacker to access the affected Atlassian application as the compromised user without completing 2FA. If the compromised account has administrative privileges, the attacker can access administrative functionality and may disable the 2FA plugin or make arbitrary administrative changes. The issue is fixed in version 3.5.0.0.
Quoted source text, attributed separately from HOL analysis.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps syracom AG/Secure Login (2FA) for Bitbucket (generic), syracom AG/Secure Login (2FA) for Confluence (generic), syracom AG/Secure Login (2FA) for Jira (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| syracom AG/Secure Login (2FA) for Bitbucketgeneric | 3.4.0.0 | Not reported |
| syracom AG/Secure Login (2FA) for Confluencegeneric | >=3.4.0.0 <3.5.0.0 | 3.5.0.0 |
| syracom AG/Secure Login (2FA) for Jirageneric | >=3.4.0.0 <3.5.0.0 | 3.5.0.0 |
Published upstream
Jun 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 21, 2026
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings such as AtlassianMobileApp or JIRA. When such a User-Agent is present, the plugin does not enforce the configured 2FA checks for protected web resources. Successful exploitation allows the attacker to access the affected Atlassian application as the compromised user without completing 2FA. If the compromised account has administrative privileges, the attacker can access administrative functionality and may disable the 2FA plugin or make arbitrary administrative changes. The issue is fixed in version 3.5.0.0.
Quoted source text, attributed separately from HOL analysis.