CVE-2026-52869: CWE-639: Authorization Bypass Through User-Controlled Key in modelcontextprotocol python-sdk
CVE-2026-52869 is a high-severity authorization bypass vulnerability in the modelcontextprotocol Python SDK (mcp). Versions prior to 1.27.2 allow an attacker with a known session ID and bearer token to inject JSON-RPC messages into sessions they did not create. This occurs because the SDK routes requests based solely on session identifiers without verifying the authenticated principal. The issue is fixed in version 1.27.2.
AI Analysis
Technical Summary
The Model Context Protocol (MCP) Python SDK, known as mcp on PyPI, prior to version 1.27.2, contains an authorization bypass vulnerability (CWE-639). The SSE and stateful Streamable HTTP transports (mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager) route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header. They do not verify that the authenticated principal making the request is the creator of the session. This flaw allows a different client authenticated with a bearer token, who knows a valid session ID, to inject JSON-RPC messages into that session. The vulnerability has a CVSS 3.1 base score of 7.1 (high severity), reflecting network attack vector, high impact on confidentiality and integrity, and low impact on availability. The issue is resolved in version 1.27.2.
Potential Impact
An attacker with a bearer token and knowledge of a valid session ID can inject unauthorized JSON-RPC messages into another client's session. This compromises confidentiality and integrity of the session data, potentially allowing unauthorized actions or data manipulation within the affected session. Availability impact is low. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Upgrade to version 1.27.2 or later of the modelcontextprotocol Python SDK, where this authorization bypass vulnerability is fixed. Patch status is confirmed by the version fix noted in the description. No other mitigation steps are indicated by the vendor advisory.
CVE-2026-52869: CWE-639: Authorization Bypass Through User-Controlled Key in modelcontextprotocol python-sdk
Description
CVE-2026-52869 is a high-severity authorization bypass vulnerability in the modelcontextprotocol Python SDK (mcp). Versions prior to 1.27.2 allow an attacker with a known session ID and bearer token to inject JSON-RPC messages into sessions they did not create. This occurs because the SDK routes requests based solely on session identifiers without verifying the authenticated principal. The issue is fixed in version 1.27.2.
CVSS v3.1
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Model Context Protocol (MCP) Python SDK, known as mcp on PyPI, prior to version 1.27.2, contains an authorization bypass vulnerability (CWE-639). The SSE and stateful Streamable HTTP transports (mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager) route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header. They do not verify that the authenticated principal making the request is the creator of the session. This flaw allows a different client authenticated with a bearer token, who knows a valid session ID, to inject JSON-RPC messages into that session. The vulnerability has a CVSS 3.1 base score of 7.1 (high severity), reflecting network attack vector, high impact on confidentiality and integrity, and low impact on availability. The issue is resolved in version 1.27.2.
Potential Impact
An attacker with a bearer token and knowledge of a valid session ID can inject unauthorized JSON-RPC messages into another client's session. This compromises confidentiality and integrity of the session data, potentially allowing unauthorized actions or data manipulation within the affected session. Availability impact is low. There are no known exploits in the wild as of the published date.
Mitigation Recommendations
Upgrade to version 1.27.2 or later of the modelcontextprotocol Python SDK, where this authorization bypass vulnerability is fixed. Patch status is confirmed by the version fix noted in the description. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-08T21:44:27.363Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a57eb0b68715ace4363c891
Added to database: 07/15/2026, 20:18:19 UTC
Last enriched: 07/22/2026, 23:03:05 UTC
Last updated: 08/28/2026, 22:52:11 UTC
Views: 110
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.