MCPA-2026-0022
highauth-missingCVSS 7.5
Dynatrace MCP Server unauthenticated HTTP MCP tool invocation (GHSA-p7w7-4929-vpj5)
@dynatrace-oss/dynatrace-mcp-server 1.8.7 and earlier, when run in HTTP mode, exposes the MCP endpoint without any authentication: anyone who can reach the port can invoke every MCP tool with the server's configured Dynatrace credentials (reading monitoring data, executing DQL, creating workflows). Fixed in 2.0.0, which adds required authentication for HTTP transport (PR #536).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @dynatrace-oss/dynatrace-mcp-server | >= 0, < 2.0.0 |
Identifiers
GHSA-p7w7-4929-vpj5CWE-306
References
- advisory https://github.com/advisories/GHSA-p7w7-4929-vpj5
- advisory https://github.com/dynatrace-oss/dynatrace-mcp/security/advisories/GHSA-p7w7-4929-vpj5
- fix https://github.com/dynatrace-oss/dynatrace-mcp/pull/536
- fix https://github.com/dynatrace-oss/dynatrace-mcp/commit/8f12972481e9165e8bd24d63b0a9e71976f85a43
Timeline
- Published: 2026-07-31