← advisory ledger

ADVISORY UNAUTH-2026-0028
TYPE exposure-class
PRODUCT MCP
SEVERITY CRITICAL

CRITICAL

MCP server exposed without authentication

published 2026-08-05 · updated 2026-08-05

Why it matters

Your MCP server answers anyone on the internet — via an open SSE/HTTP transport, a public /messages/ session surface, a /.well-known MCP discovery card, or a static tools catalog on that card (the GET equivalent of unauthenticated tools/list). MCP servers are built for local use and ship with no auth by default; once public, strangers can discover and often CALL your tools (files, shell, databases — whatever the server exposes). That is anonymous tool execution, not just information disclosure.

What a probe sees

GET /sse or /mcp answers an MCP transport (SSE stream or JSON-RPC) without auth — tool discovery is open.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

tool-transport

In the wild

HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE mcp
PROBES (30d) 304
FIRST SEEN 2026-08-02
LAST SEEN 2026-08-05

Day-granularity probe counts from the unauth.dev botwatch honeypot (304 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.

Fix it

Fix card: mcp-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0028 — observed 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0028. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.