← Terug naar overzicht

CVE-2026-79750 affects MCPHub, a unified hub for managing and orchestrating multiple MCP servers and APIs. Prior to version 1.0.30, a broken access control vulnerability exists in the tool-execution API, which fails to enforce ownership/scoping rules that are otherwise applied to list views and config edits. Any authenticated non-admin user can invoke tools on MCP servers owned by other users, even servers they cannot view via GET /api/servers. This cross-tenant compromise enables attackers to read arbitrary host files (e.g., /etc/passwd, secrets) and conduct Server-Side Request Forgery (SSRF) using the victim server owner's cloud API keys and credentials. The vulnerability has been patched in MCPHub version 1.0.30. Organizations running earlier versions should upgrade immediately to prevent unauthorized cross-tenant access and potential data exfiltration.

Affected products

  • MCPHub

Related CVE's

  • CVE-2026-79750

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Identity & Access
  • Web Technologies