Authentication Bypass in MCPHub OAuth 2.0 Authorization Server
CVE-2026-90474

7.6HIGH

Key Information:

Vendor

Samanhappy

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-90474?

MCPHub prior to version 1.0.32 contains a significant vulnerability within its OAuth 2.0 authorization server. By default, client authentication is disabled, and the enforcement of Proof Key for Code Exchange (PKCE) is optional, making it susceptible to exploitation. Attackers can intercept authorization codes and gain unauthorized access to victim accounts by exchanging these codes for access tokens without needing the client secret or PKCE verifier, thereby compromising account security and user privileges.

Affected Version(s)

mcphub 0 < 1.0.32

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wayde Shi (PayPal Cyber Security Team)
.