Authorization Bypass in MCPHub's System Configuration API
CVE-2026-79744
8.8HIGH
What is CVE-2026-79744?
MCPHub, a versatile platform for the management and orchestration of multiple MCP servers and APIs, suffers from an authorization bypass vulnerability in its PUT /api/system-config endpoint, which lacks proper checks before executing configuration updates. This vulnerability allows unauthenticated users to exploit the handler updateSystemConfig, bypassing administrative restrictions. The issue has been addressed in version 1.0.29, where enhanced authorization protocols were implemented to secure the endpoint effectively. Users are advised to upgrade promptly to mitigate any potential risks associated with this vulnerability.
Affected Version(s)
mcphub < 1.0.29
