Vulnerability  ·  2026-09-30

MetaMCP cross-tenant IDOR lets attacker execute another tenant's private MCP tools with forwarded credentials

VulnerabilityHigh impactGlobalCVE-2026-79537
NVD published CVE-2026-79537 on 2026-09-29. MetaMCP's transport session store is keyed only by the client-supplied mcp-session-id header with no owner/namespace/endpoint binding; per-endpoint authorization checks only the URL's owner, never the session. Session IDs leak via an unauthenticated health endpoint, enabling cross-tenant tool invocation and data exfiltration.
Classic agentic-identity boundary failure: session IDs act as bearer credentials for MCP tool execution in a multi-tenant agent platform, so a neighboring tenant can run another tenant's private MCP tools (database, code, cloud) with the victim's forwarded credentials — data theft across AI tenant boundaries.
Unauthenticated attacker reads active session IDs and namespace UUIDs from GET /metamcp/health/sessions, then supplies another tenant's session id in the mcp-session-id header to list/execute that tenant's private MCP tools using the victim's forwarded credentials.
metatool-ai MetaMCP through 2.4.22 (session dispatch in session-lifetime-manager.ts)
Bind MCP sessions to owner/namespace/endpoint, authenticate session access, and stop exposing session IDs via /metamcp/health/sessions; monitor MetaMCP releases and the TraceForce advisory.
NVD CVE-2026-79537TraceForce advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →