Skip to content

MCPA-2026-0038

highauth-missingCVSS 8.1

NetLicensing-MCP HTTP mode uses the server-side NetLicensing API key for unauthenticated requests (CVE-2026-54446)

netlicensing-mcp (PyPI) through 0.1.5: in HTTP transport mode, ApiKeyMiddleware forwards requests that carry no client API key unconditionally, and the downstream HTTP client falls back to the server's own NetLicensing API key — unauthenticated remote callers act with the operator's full API privileges. Fixed in 0.1.6.

Affected packages

EcosystemPackageAffected versions
pypinetlicensing-mcp
>= 0, < 0.1.6

Identifiers

CVE-2026-54446GHSA-x9vc-9ffq-p3gjCWE-306

References

Timeline

  • Published: 2026-07-14

← All advisories