NewsSecurity Vulnerabilities

MCPHub Authentication Bypass Vulnerability (CVE-2026-90474)

A newly disclosed security vulnerability in MCPHub could allow attackers to bypass authentication and gain unauthorised access to systems using vulnerable versions of the software.

Tracked as CVE-2026-90474, the flaw affects MCPHub versions before 1.0.32 and is described as an authentication bypass in its embedded OAuth 2.0 authorisation server. The vulnerability has been rated as a medium-severity issue with a CVSS score of 6.8.

MCPHub is designed to work with Model Context Protocol (MCP) services, which allow AI applications and agents to interact with external tools and services. Its authentication infrastructure therefore plays an important role in controlling who can access connected MCP resources.

According to vulnerability information currently available, CVE-2026-90474 can be exploited by attackers to circumvent authentication controls. The flaw could potentially allow an attacker to obtain access beyond what should normally be permitted, depending on how MCPHub is configured and what services are connected to the installation.

The vulnerability is particularly relevant as MCP-based systems are increasingly being used to connect AI applications with external data sources, APIs and other tools. A weakness in authentication could therefore create additional security risks where an MCPHub installation has access to sensitive systems or information.

Users urged to update

MCPHub users should check whether they are running a vulnerable release and update to version 1.0.32 or later where available.

Organisations should also review authentication configurations and examine access logs for unusual activity, particularly where MCPHub is exposed to the internet or provides access to sensitive internal services.

At present, there is no indication from the sources reviewed that CVE-2026-90474 has been added to the CISA Known Exploited Vulnerabilities catalogue. However, its authentication-bypass nature means administrators should not ignore the issue.

With AI infrastructure becoming increasingly connected to corporate systems, vulnerabilities affecting authentication and access controls within MCP platforms could become increasingly important security concerns.

CVE: CVE-2026-90474
Product: MCPHub
Affected versions: Before 1.0.32
Severity: Medium
CVSS: 6.8
Vulnerability: Authentication bypass
Fix: Update to MCPHub 1.0.32 or later

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.