Incorrect authorization in nginx-ui - #VU152977
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to invoke MCP tools classified as write operations.
The vulnerability exists due to incorrect authorization in the MCP authorization middleware when processing tools/call requests containing a valid JSON-RPC request followed by another JSON value. A remote user can submit a crafted request to invoke write-class MCP tools.
The issue affects read-scoped MCP service tokens and user sessions that have not completed secure-session step-up.