{
  "id": 11817558,
  "title": "MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs",
  "url": "https://urgent.news/2026/10/04/mcp-servers-had-a-rough-48-hours-4-unauthenticated-cves",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T01:47:47.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kielltampubolon/mcp-servers-had-a-rough-48-hours-4-unauthenticated-cves-4oco"
  },
  "original_language": "en",
  "account": "During the past two days, four Model Context Protocol (MCP) servers were found to have unauthenticated Common Vulnerabilities and Exposures (CVEs). These vulnerabilities allowed unauthorized access to sensitive information and execution of arbitrary code on the affected servers.\n\nThe four CVEs include:\n\n1. CVE-2026-90898: The Bifrost MCP gateway (maximhq, Go) had a flaw that allowed attackers to execute arbitrary commands and read files on the host system without any authentication. The vulnerability was fixed in version 2.1.27, but the underlying issue persisted.\n\n2. CVE-2026-53710: The IBM MCP MySQL tool allowed attackers to gain full access to the MySQL database and filesystem by exploiting a lack of authentication. The fix for this vulnerability was included in version 1.0.2.\n\n3. CVE-2026-59971: The MySQL MCP server (PyPI) had a similar issue, granting unauthorized access to the MySQL database and filesystem, which could lead to the execution of arbitrary code.\n\n4. CVE-2026-61560: The npm package @zereight/mcp-gitlab suffered from an authentication bypass, enabling attackers to manipulate GitLab repositories and retrieve sensitive information such as GITLAB_PERSONAL_ACCESS_TOKEN. The vulnerability was fixed in version 2.1.27, but the fix was not widely adopted.\n\nThese four vulnerabilities highlight the importance of implementing proper authentication mechanisms and input validation in MCP servers to prevent unauthorized access and potential exploitation. The fact that no write-ups were found on popular tech platforms like Hacker News or Dev.to suggests that the affected organizations may not have been aware of the issue, further emphasizing the need for swift action to address and remediate these vulnerabilities.",
  "summary": "Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication. A GitLab server that reads any file on its host and uploads it wherever the request asks. A gateway that runs a program chosen by whoever can POST to it. A MySQL tool that hands its database and…",
  "key_points": [
    "Four unauthenticated CVEs discovered in MCP servers",
    "Vulnerabilities allow unauthorized access and code execution",
    "Fixes available but not widely adopted"
  ],
  "editors_take": "The newly disclosed unauthenticated CVEs in multiple MCP servers underscore the need for stricter authentication and validation measures to prevent exploitation and data breaches in affected systems.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}