What happened
NVD published CVE-2026-79537 on 2026-09-29. MetaMCP's transport session store is keyed only by the client-supplied mcp-session-id header with no owner/namespace/endpoint binding; per-endpoint authorization checks only the URL's owner, never the session. Session IDs leak via an unauthenticated health endpoint, enabling cross-tenant tool invocation and data exfiltration.
Why it matters
Classic agentic-identity boundary failure: session IDs act as bearer credentials for MCP tool execution in a multi-tenant agent platform, so a neighboring tenant can run another tenant's private MCP tools (database, code, cloud) with the victim's forwarded credentials — data theft across AI tenant boundaries.
Attack vector
Unauthenticated attacker reads active session IDs and namespace UUIDs from GET /metamcp/health/sessions, then supplies another tenant's session id in the mcp-session-id header to list/execute that tenant's private MCP tools using the victim's forwarded credentials.
Affected systems
metatool-ai MetaMCP through 2.4.22 (session dispatch in session-lifetime-manager.ts)
Mitigation
Bind MCP sessions to owner/namespace/endpoint, authenticate session access, and stop exposing session IDs via /metamcp/health/sessions; monitor MetaMCP releases and the TraceForce advisory.