Authorization Bypass in MCPHub's System Configuration API
CVE-2026-79744

8.8HIGH

Key Information:

Vendor

Samanhappy

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-79744?

MCPHub, a versatile platform for the management and orchestration of multiple MCP servers and APIs, suffers from an authorization bypass vulnerability in its PUT /api/system-config endpoint, which lacks proper checks before executing configuration updates. This vulnerability allows unauthenticated users to exploit the handler updateSystemConfig, bypassing administrative restrictions. The issue has been addressed in version 1.0.29, where enhanced authorization protocols were implemented to secure the endpoint effectively. Users are advised to upgrade promptly to mitigate any potential risks associated with this vulnerability.

Affected Version(s)

mcphub < 1.0.29

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.