MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs
Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and…
During the past two days, four Model Context Protocol (MCP) servers were found to have unauthenticated Common Vulnerabilities and Exposures (CVEs). These vulnerabilities allowed unauthorized access to sensitive information and execution of arbitrary code on the affected servers.
The four CVEs include:
1. CVE-2026-90898: The Bifrost MCP gateway (maximhq, Go) had a flaw that allowed attackers to execute arbitrary commands and read files on the host system without any authentication. The vulnerability was fixed in version 2.1.27, but the underlying issue persisted.
2. CVE-2026-53710: The IBM MCP MySQL tool allowed attackers to gain full access to the MySQL database and filesystem by exploiting a lack of authentication. The fix for this vulnerability was included in version 1.0.2.
3. CVE-2026-59971: The MySQL MCP server (PyPI) had a similar issue, granting unauthorized access to the MySQL database and filesystem, which could lead to the execution of arbitrary code.
4. CVE-2026-61560: The npm package @zereight/mcp-gitlab suffered from an authentication bypass, enabling attackers to manipulate GitLab repositories and retrieve sensitive information such as GITLAB_PERSONAL_ACCESS_TOKEN. The vulnerability was fixed in version 2.1.27, but the fix was not widely adopted.
These four vulnerabilities highlight the importance of implementing proper authentication mechanisms and input validation in MCP servers to prevent unauthorized access and potential exploitation. The fact that no write-ups were found on popular tech platforms like Hacker News or Dev.to suggests that the affected organizations may not have been aware of the issue, further emphasizing the need for swift action to address and remediate these vulnerabilities.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.