PT-2026-76866 · Onyx · Onyx

CVE-2026-71424

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Onyx versions prior to 3.1.10 Onyx versions prior to 3.2.14 Onyx versions prior to 4.0.0
Description An issue exists where the 'GET /api/mcp/servers' and 'GET /api/mcp/servers/persona/{persona id}' endpoints expose the OAuth Authorization header of other users. This occurs because the set tokens() and set client info() functions in OnyxTokenStorage copy per-user tokens into a shared admin MCPConnectionConfig row. Subsequently, the db mcp server to api mcp server() function returns this row via auth template.headers to any user with BASIC ACCESS privileges.
Recommendations Update to version 3.1.10. Update to version 3.2.14. Update to version 4.0.0.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71424
GHSA-Q62F-RV3H-F822

Affected Products

Onyx