Description
MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.
Published: 2026-09-12
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account access via OAuth 2.0 authentication bypass
Action: Patch Immediately
AI Analysis

Impact

MCPHub versions prior to 1.0.32 embed an OAuth 2.0 authorization server that, by default, does not require client authentication and allows optional PKCE enforcement. An attacker who obtains an authorization code can redeem it for an access token without providing a client secret or a PKCE verifier, thereby bypassing the intended authentication checks and gaining authenticated access to a victim’s account.

Affected Systems

The vulnerability affects the MCPHub product from the vendor samanhappy, specifically versions released before 1.0.32.

Risk and Exploitability

The CVSS score of 7.6 indicates a high‑severity flaw that threatens confidentiality, integrity, and availability by allowing attackers to impersonate users. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Attackers can exploit this by intercepting an authorization code over an insecure channel and exchanging it for an access token without the required client credentials or PKCE verifier, creating an unauthorized access path to victim accounts.

Generated by OpenCVE AI on September 15, 2026 at 18:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MCPHub to v1.0.32 or newer, which enables client authentication and PKCE enforcement by default.
  • Reconfigure the embedded OAuth server to require client authentication and enforce PKCE on all grant types if an immediate upgrade is not feasible.
  • Ensure all OAuth traffic is transmitted over TLS to prevent interception of authorization codes.

Generated by OpenCVE AI on September 15, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Samanhappy
Samanhappy mcphub
Vendors & Products Samanhappy
Samanhappy mcphub

Sat, 12 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.
Title MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samanhappy Mcphub
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:45.208Z

Reserved: 2026-09-12T02:03:32.649Z

Link: CVE-2026-90474

cve-icon Vulnrichment

Updated: 2026-09-15T16:58:37.842Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T11:16:34.483

Modified: 2026-09-23T17:17:47.390

Link: CVE-2026-90474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses