Impact
NetLicensing MCP Server allows HTTP requests to the /mcp endpoint to bypass authentication when a server‑side API key is configured. The missing validation in the ApiKeyMiddleware causes the request context to fall back to the operator’s NETLICENSING_API_KEY and authenticates all downstream NetLicensing REST calls under that account. An unauthenticated attacker can therefore enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and delete data, with no user interaction required. This flaw corresponds to CWE‑306: Incorrect Authentication.
Affected Systems
The vulnerability exists in Labs64’s NetLicensing‑MCP product before version 0.1.6. Any HTTP deployment using a server‑side API key and running an older release is affected. Versions 0.1.6 and later contain the fix.
Risk and Exploitability
The CVSS score of 8.1 denotes high severity. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw simply by sending unauthenticated HTTP requests to the /mcp endpoint; no credentials or special access are needed. If the server is publicly reachable, the attacker can gain full operator‑level control over the licensing service, potentially exposing sensitive data and performing destructive operations.
OpenCVE Enrichment
Github GHSA