Description
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication. The downstream api_key_ctx in src/netlicensing_mcp/client.py then falls back to the operator's NETLICENSING_API_KEY and authenticates upstream NetLicensing REST API calls under the operator account. An unauthenticated attacker can invoke MCP tools to enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and execute destructive delete operations. The issue affects HTTP deployments configured with a server-side key and does not require user interaction. This issue is fixed in version 0.1.6.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Remote Access allowing enumeration and destructive operations
Action: Patch Immediately
AI Analysis

Impact

NetLicensing MCP Server allows HTTP requests to the /mcp endpoint to bypass authentication when a server‑side API key is configured. The missing validation in the ApiKeyMiddleware causes the request context to fall back to the operator’s NETLICENSING_API_KEY and authenticates all downstream NetLicensing REST calls under that account. An unauthenticated attacker can therefore enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and delete data, with no user interaction required. This flaw corresponds to CWE‑306: Incorrect Authentication.

Affected Systems

The vulnerability exists in Labs64’s NetLicensing‑MCP product before version 0.1.6. Any HTTP deployment using a server‑side API key and running an older release is affected. Versions 0.1.6 and later contain the fix.

Risk and Exploitability

The CVSS score of 8.1 denotes high severity. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw simply by sending unauthenticated HTTP requests to the /mcp endpoint; no credentials or special access are needed. If the server is publicly reachable, the attacker can gain full operator‑level control over the licensing service, potentially exposing sensitive data and performing destructive operations.

Generated by OpenCVE AI on September 19, 2026 at 02:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NetLicensing‑MCP to version 0.1.6 or later, which implements proper authentication for the /mcp endpoint.
  • If upgrading is not immediately possible, restrict access to the /mcp endpoint by firewall or network segmentation so that only trusted hosts can reach it.
  • Verify that any deployments no longer use the legacy server‑side API key pattern and that empty or missing API key fields are handled securely.

Generated by OpenCVE AI on September 19, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x9vc-9ffq-p3gj NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Labs64
Labs64 netlicensing-mcp
Vendors & Products Labs64
Labs64 netlicensing-mcp

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication. The downstream api_key_ctx in src/netlicensing_mcp/client.py then falls back to the operator's NETLICENSING_API_KEY and authenticates upstream NetLicensing REST API calls under the operator account. An unauthenticated attacker can invoke MCP tools to enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and execute destructive delete operations. The issue affects HTTP deployments configured with a server-side key and does not require user interaction. This issue is fixed in version 0.1.6.
Title NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Labs64 Netlicensing-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:14:40.858Z

Reserved: 2026-06-15T15:30:40.317Z

Link: CVE-2026-54446

cve-icon Vulnrichment

Updated: 2026-09-17T19:14:34.445Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:16:46.040

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function