PT-2026-81459 · Unknown · Genieacs-Mcp

·

CVE-2026-55637

·

Published

2026-08-25

·

Updated

2026-09-04

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions genieacs-mcp versions prior to 0.3.2
Description The Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp endpoint on the default address 127.0.0.1:8080 when the MCP AUTH TOKEN variable is unset. The server fails to validate the Host or Origin headers, allowing a malicious website to use DNS rebinding to send browser requests to the loopback listener. This enables an attacker to initialize an MCP session, list tools, and invoke operations against the GenieACS NBI configured by ACS URL. Successful exploitation can expose or modify CPE management state, including device reboots, firmware tasks, TR-069 parameter changes, presets, provisions, tags, connection requests, and task operations.
Recommendations Update to version 0.3.2. As a temporary mitigation, set the MCP AUTH TOKEN variable to require authentication for the HTTP listener. Restrict the use of the HTTP transport by using TRANSPORT=stdio to avoid exposing an HTTP listener.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55637
GHSA-CMWV-WF9P-P8WX
GO-2026-6295
OPENSUSE-SU-2026:21761-1

Affected Products

Genieacs-Mcp