Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90474— MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass

Quick assessment

Affected
samanhappy mcphub
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MCPHub 1.0.32 之前的版本中存在一个认证绕过漏洞,位于其内置的 OAuth 2.0 授权服务器中。在该服务器中,客户端身份验证默认处于禁用状态,而 PKCE 强制要求是可选的。攻击者通过拦截获取授权码后,可以在不提供客户端密钥或 PKCE 验证器的情况下,将授权码兑换为访问令牌,从而获得对受害者账户及其权限的访问权。

CVSS 6.8 · Medium

Possible ATT&CK Techniques 1 AI

T1040 · Network Sniffing

Affected Version Matrix 1

VendorProduct Version RangeStatus
samanhappy mcphub < 1.0.32 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
samanhappy mcphub 0 ~ 1.0.32 -

II. Public POCs for CVE-2026-90474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90474

登录查看更多情报信息。

Patches & Fixes for CVE-2026-90474 (2)

Vendor Advisories for CVE-2026-90474 (2)

Vendor Pages for CVE-2026-90474 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-90474

No comments yet


Leave a comment