Missing Authorization in MCP Gateway - #VU139379

 

Missing Authorization in MCP Gateway - #VU139379

Published: July 26, 2026


Vulnerability identifier: #VU139379
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the host.

The vulnerability exists due to missing authorization in the dynamic management tools and container volume handling when supplying crafted configuration to dynamic tools. A remote user can provide a sensitive host path as a bind mount value to execute arbitrary code on the host.

Exploitation requires dynamic tools to be enabled and the gateway to have Docker API authority.


Affected software

MCP Gateway

Remediation

Install security update from vendor's website.

MCP Gateway - update to 0.43.1

External References

Related Security Bulletins