Unauthorized Access in MCPHub API Controller by Samanhappy
CVE-2026-79745

7.1HIGH

Key Information:

Vendor

Samanhappy

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-79745?

Prior to version 1.0.32, MCPHub's built-in prompt and resource controllers lacked essential role checking, allowing non-admin users to create, overwrite, and shadow global prompt templates and resources. These vulnerabilities stem from the mutating POST/PUT routes that bypass admin verification. The unauthorized modifications lead to integrity violations, impacting all users and enabling potential stored prompt injections into LLM sessions as a downstream effect. This serious oversight presents significant risks to data integrity within shared resources, making prompt updates a shared concern. The issue was addressed in version 1.0.32.

Affected Version(s)

mcphub < 1.0.32

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.