ADVISORY UNAUTH-2026-0028
TYPE exposure-class
PRODUCT MCP
SEVERITY CRITICAL
MCP server exposed without authentication
published 2026-08-05 · updated 2026-08-05
Why it matters
Your MCP server answers anyone on the internet — via an open SSE/HTTP transport, a public /messages/ session surface, a /.well-known MCP discovery card, or a static tools catalog on that card (the GET equivalent of unauthenticated tools/list). MCP servers are built for local use and ship with no auth by default; once public, strangers can discover and often CALL your tools (files, shell, databases — whatever the server exposes). That is anonymous tool execution, not just information disclosure.
What a probe sees
GET /sse or /mcp answers an MCP transport (SSE stream or JSON-RPC) without auth — tool discovery is open.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
tool-transport
In the wild
HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE mcp
PROBES (30d) 304
FIRST SEEN 2026-08-02
LAST SEEN 2026-08-05
Day-granularity probe counts from the unauth.dev botwatch honeypot (304 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.
Fix it
References
- https://modelcontextprotocol.io/specification/2025-06-18/basic/transports
- https://modelcontextprotocol.io/docs/concepts/transports
- https://datatracker.ietf.org/doc/html/draft-serra-mcp-discovery-uri
Cite this record
unauth.dev advisory UNAUTH-2026-0028 — observed 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0028. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.