Remote Authentication Bypass in AgenticMail by Agentic
CVE-2026-50287

8.7HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-50287?

AgenticMail, a tool that provides AI agents with email addresses and phone numbers, contains a vulnerability prior to version 0.9.27. This flaw allows a remote client to connect to the /mcp endpoint without any HTTP authentication, resulting in unauthorized access to the tool's functionalities. The issue arises when AgenticMail is launched with the Streamable HTTP transport option enabled, either through the command line or environment variables. This vulnerability poses a significant risk, allowing unauthorized users to initialize a session and use tools directly. The problem has been addressed in version 0.9.27.

Affected Version(s)

agenticmail < 0.9.27

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.