Authentication Bypass in MCPHub OAuth 2.0 Authorization Server
CVE-2026-90474
7.6HIGH
What is CVE-2026-90474?
MCPHub prior to version 1.0.32 contains a significant vulnerability within its OAuth 2.0 authorization server. By default, client authentication is disabled, and the enforcement of Proof Key for Code Exchange (PKCE) is optional, making it susceptible to exploitation. Attackers can intercept authorization codes and gain unauthorized access to victim accounts by exchanging these codes for access tokens without needing the client secret or PKCE verifier, thereby compromising account security and user privileges.
Affected Version(s)
mcphub 0 < 1.0.32
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Wayde Shi (PayPal Cyber Security Team)
