Skip to content

MCPA-2026-0022

highauth-missingCVSS 7.5

Dynatrace MCP Server unauthenticated HTTP MCP tool invocation (GHSA-p7w7-4929-vpj5)

@dynatrace-oss/dynatrace-mcp-server 1.8.7 and earlier, when run in HTTP mode, exposes the MCP endpoint without any authentication: anyone who can reach the port can invoke every MCP tool with the server's configured Dynatrace credentials (reading monitoring data, executing DQL, creating workflows). Fixed in 2.0.0, which adds required authentication for HTTP transport (PR #536).

Affected packages

EcosystemPackageAffected versions
npm@dynatrace-oss/dynatrace-mcp-server
>= 0, < 2.0.0

Identifiers

GHSA-p7w7-4929-vpj5CWE-306

References

Timeline

  • Published: 2026-07-31

← All advisories