Unauthenticated MCP Server in GenieACS by GeiserX
CVE-2026-55637

8.8HIGH

Key Information:

Vendor

Geiserx

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55637?

The genieacs-mcp server, developed by GeiserX, contains a vulnerability that exposes a Streamable HTTP transport on the default loopback address, allowing attackers to exploit DNS rebinding techniques. When the MCP_AUTH_TOKEN is unset, invalid Host or Origin headers can be sent to the unauthenticated /mcp listener, enabling malicious users to manipulate or retrieve critical CPE management states. This includes operations such as device reboots, firmware updates, and parameter modifications. The issue has been addressed in version 0.3.2.

Affected Version(s)

genieacs-mcp < 0.3.2

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.