MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials (CVE-2026-77254) | HOL Guard CVE