Missing Authentication for Critical Function in MCP Gateway - #VU139381

 

Missing Authentication for Critical Function in MCP Gateway - #VU139381

Published: July 26, 2026


Vulnerability identifier: #VU139381
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthenticated access to proxied tools and act with the user's stored secrets and OAuth tokens.

The vulnerability exists due to missing authentication for critical function in the /sse and /mcp HTTP endpoints when running the gateway in container mode with an HTTP transport. A remote attacker can send requests without authentication to gain unauthenticated access to proxied tools and act with the user's stored secrets and OAuth tokens.

The issue occurs because the bearer-token authentication middleware is not installed in container mode, and requests without an Origin header are allowed.


Affected software

MCP Gateway

Remediation

Install security update from vendor's website.

MCP Gateway - update to 0.43.1

External References

Related Security Bulletins