Description
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the streamable-http transport can therefore send any X-Pipeboard-Token value, pass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator's META_ACCESS_TOKEN. Subsequent MCP tools execute with the operator's Meta credentials and can read or modify the operator's Meta Ads data. Deployments using the default stdio transport or without META_ACCESS_TOKEN are not affected. This issue is fixed in version 1.0.115.
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch Now
AI Analysis

Impact

Meta Ads MCP is a Model Context Protocol server that enables AI assistants to run Meta Ads. Prior to version 1.0.115, the AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py only rejects HTTP MCP requests when both auth_token and pipeboard_token are absent. In addition, extract_token_from_headers() does not treat X‑Pipeboard‑Token as a primary credential. A network caller that uses the streamable‑http transport can therefore send any X‑Pipeboard‑Token value, bypass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator’s META_ACCESS_TOKEN. Subsequent MCP tools then execute with the operator’s Meta credentials, allowing the attacker to read or modify the operator’s Meta Ads data. This flaw is a CWE‑287 improper authentication vulnerability.

Affected Systems

The flaw affects installations of pipeboard‑co earlier than 1.0.115. Deployments that use the default stdio transport or have not defined a META_ACCESS_TOKEN are not susceptible.

Risk and Exploitability

The CVSS score of 7.4 indicates a high impact severity. The EPSS score is < 1%, meaning the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network-based attacker able to send a request with a crafted X‑Pipeboard‑Token header via the streamable‑http transport; the attacker need not have any prior authentication. Once the request passes the bypass, the server operates with the operator’s credentials, providing full access to Meta Ads resources.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Meta Ads MCP to version 1.0.115 or later, which implements proper token validation in AuthInjectionMiddleware.
  • Ensure the server’s META_ACCESS_TOKEN is stored securely and not streamable‑http transport or X‑Pipeboard‑Token header usage is required, audit the server to enforce credential checks or consider disabling those transport options until a patch is applied.
  • Revoke or rotate the current META_ACCESS_TOKEN and audit all configuration settings to confirm that no client is authorized to use the X‑Pipeboard‑Token header until the official update is applied.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2v2f-mvfg-ph56 meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Pipeboard-co
Pipeboard-co meta-ads-mcp
Vendors & Products Pipeboard-co
Pipeboard-co meta-ads-mcp

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the streamable-http transport can therefore send any X-Pipeboard-Token value, pass the guard without establishing authentication context, and cause get_auth_token() to fall back to the server operator's META_ACCESS_TOKEN. Subsequent MCP tools execute with the operator's Meta credentials and can read or modify the operator's Meta Ads data. Deployments using the default stdio transport or without META_ACCESS_TOKEN are not affected. This issue is fixed in version 1.0.115.
Title Meta Ads MCP: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Pipeboard-co Meta-ads-mcp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:23:45.439Z

Reserved: 2026-06-15T19:04:14.456Z

Link: CVE-2026-54547

cve-icon Vulnrichment

Updated: 2026-09-17T16:23:39.473Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:22.927

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54547

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses