Unauthenticated MCP Server in GenieACS by GeiserX
CVE-2026-55637
8.8HIGH
What is CVE-2026-55637?
The genieacs-mcp server, developed by GeiserX, contains a vulnerability that exposes a Streamable HTTP transport on the default loopback address, allowing attackers to exploit DNS rebinding techniques. When the MCP_AUTH_TOKEN is unset, invalid Host or Origin headers can be sent to the unauthenticated /mcp listener, enabling malicious users to manipulate or retrieve critical CPE management states. This includes operations such as device reboots, firmware updates, and parameter modifications. The issue has been addressed in version 0.3.2.
Affected Version(s)
genieacs-mcp < 0.3.2
