Vulnerability  ·  2026-09-19

NetLicensing MCP Server — unauthenticated tool access when API key headers omitted

VulnerabilityHigh impactGlobalCVE-2026-54446
The MCP server exposing NetLicensing's software-licensing lifecycle to AI agents fails to enforce authentication when standard credential headers are absent, allowing unauthenticated tool invocation.
This allows an unauthenticated party to manipulate software licensing operations via the agentic interface, but the narrow, single-vendor deployment keeps this a lower-tier catalogued finding.
Network-reachable HTTP transport requests to /mcp that omit the x-netlicensing-api-key header, Authorization Bearer header, and apikey query parameter are still processed, allowing unauthenticated access to licensing-management tool calls.
NetLicensing MCP Server < 0.1.6
Upgrade to NetLicensing MCP Server 0.1.6 or later.
GitHub commit (fix)NVD CVE-2026-54446
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →