Skip to content

MCPA-2026-0001

highssrfCVSS 8.8

Azure MCP Server server-side request forgery allows privilege elevation (CVE-2026-26118)

Server-Side Request Forgery (SSRF) in Microsoft's Azure MCP Server allows an authorized attacker to elevate privileges over a network. Affects the npm, NuGet and PyPI distributions of Azure MCP Server Tools.

Assigned CWE-918 (SSRF) by Microsoft. Affected: 1.x prior to 1.0.2 and 2.0.0 pre-releases prior to 2.0.0-beta.17 (npm @azure/mcp and NuGet Azure.Mcp); PyPI msmcp-azure 2.0.0b14 to before 2.0.0b17. Patched in 1.0.2 and 2.0.0-beta.17 (PyPI 2.0.0b17).

Affected packages

EcosystemPackageAffected versions
npm@azure/mcp
>= 1.0.0, < 1.0.2
>= 2.0.0-beta.1, < 2.0.0-beta.17
nugetAzure.Mcp
>= 1.0.0, < 1.0.2
>= 2.0.0-beta.1, < 2.0.0-beta.17
pypimsmcp-azure
>= 2.0.0b14, < 2.0.0b17

Identifiers

CVE-2026-26118GHSA-hhfx-wfvq-7g9cCWE-918

References

Timeline

  • Published: 2026-03-10

← All advisories