Remote Authentication Bypass in AgenticMail by Agentic
CVE-2026-50287
8.7HIGH
What is CVE-2026-50287?
AgenticMail, a tool that provides AI agents with email addresses and phone numbers, contains a vulnerability prior to version 0.9.27. This flaw allows a remote client to connect to the /mcp endpoint without any HTTP authentication, resulting in unauthorized access to the tool's functionalities. The issue arises when AgenticMail is launched with the Streamable HTTP transport option enabled, either through the command line or environment variables. This vulnerability poses a significant risk, allowing unauthorized users to initialize a session and use tools directly. The problem has been addressed in version 0.9.27.
Affected Version(s)
agenticmail < 0.9.27
