logo

Critical MCP Toolbox Vulnerability Exposes Enterprise Databases

ID: b69c0f57-8f17-5fcd-b331-0c1709c7630b

STIX ID: report--b69c0f57-8f17-5fcd-b331-0c1709c7630b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-31

Date Updated: 2026-05-31

Author: Ddos

...
...

Security researchers disclosed CVE-2026-9739 affecting the open-source MCP Toolbox: a hardcoded wildcard access-control header in the Server-Sent Events handler overrides CORS protections, allowing malicious websites to bypass security controls, hijack sessions, and proxy requests to exfiltrate data from linked databases (e.g., Postgres, BigQuery). Impact primarily affects deployments using the v2024-11-05 protocol; remediation is to remove the hardcoded header so global middleware correctly enforces origin restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.