SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90474

MEDIUM · CVSS 6.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

MCPHub versions prior to 1.0.32 are vulnerable to an authentication bypass in the embedded OAuth 2.0 authorization server, where client authentication is disabled by default and PKCE enforcement is optional. This flaw allows attackers to intercept authorization codes and redeem them for access tokens, potentially compromising user accounts and their privileges. Organizations using MCPHub should prioritize applying the latest updates to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90474
Severity
MEDIUM
CVSS
6.8
EPSS
0.30%

Original NVD Description

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.