Description
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized access to tenant data via insecure direct object reference
Action: Immediate Patch
AI Analysis

Impact

Metatool‑ai MetaMCP versions up to 2.4.22 implement an insecure direct object reference. The session store uses a client‑supplied request header to identify sessions but does not bind the session to the tenant, namespace or request endpoint. Based on the description, the attacker can obtain a valid session ID belonging to another tenant. This ID can be discovered by querying the publicly accessible /metamcp/health/sessions endpoint, which exposes active session IDs and namespace UUIDs. With that session ID the attacker may list and invoke tenant‑specific MCP tools and exfiltrate data using the victim’s forwarded credentials, thereby compromising confidentiality and integrity of the victim tenant’s data.

Affected Systems

The affected product is Metatool‑ai MetaMCP 2.4.22 and all earlier releases. Any deployment that has not been upgraded beyond this version is vulnerable.

Risk and Exploitability

The vulnerability is highly exploitable because the session ID is transmitted in a header with no per‑tenant binding or endpoint validation. An attacker who can read the health endpoint requires no authentication, which is typically exposed to untrusted networks. The EPSS score is not available and the flaw is not yet listed in the CISA KEV catalog. Given the lack of protections, the likelihood of exploitation is significant in environments where MetaMCP is reachable from the public internet.

Generated by OpenCVE AI on September 30, 2026 at 04:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MetaMCP to version 2.4.23 or later, which removes the IDOR flaw
  • Restrict or authenticate the /metamcp/health/sessions endpoint to prevent exposure of active session IDs
  • Modify the session validation logic to bind session IDs to the tenant owner or namespace and reject requests where the session owner does not match the targeted tenant

Generated by OpenCVE AI on September 30, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Insecure Direct Object Reference in MetaMCP Session Dispatch Allows Tenant IDOR
Weaknesses CWE-639

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-29T19:17:20.089Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79537

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T20:17:27.383

Modified: 2026-09-29T20:17:27.383

Link: CVE-2026-79537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:45:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key