Skip to main content

CVE-2026-54446: CWE-306: Missing Authentication for Critical Function in Labs64 NetLicensing-MCP

0
High
VulnerabilityCVE-2026-54446cvecve-2026-54446cwe-306
Published: 09/17/2026 (09/17/2026, 17:13:29 UTC)
Source: CVE Database V5
Vendor/Project: Labs64
Product: NetLicensing-MCP

Description

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication. The downstream api_key_ctx in src/netlicensing_mcp/client.py then falls back to the operator's NETLICENSING_API_KEY and authenticates upstream NetLicensing REST API calls under the operator account. An unauthenticated attacker can invoke MCP tools to enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and execute destructive delete operations. The issue affects HTTP deployments configured with a server-side key and does not require user interaction. This issue is fixed in version 0.1.6.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Labs64

NetLicensing-MCP

Affected versions
<0.1.6
GitHub Actionsmore threats →ai
labs64/NetLicensing-MCP
pkg:github/labs64/NetLicensing-MCP
Affected versions
<0.1.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 17:46:30 UTC

Technical Analysis

Labs64 NetLicensing-MCP Server versions before 0.1.6 have a missing authentication vulnerability (CWE-306) in the /mcp HTTP endpoint. Requests lacking the x-netlicensing-api-key header, Authorization: Bearer token, or apikey query parameter bypass ApiKeyMiddleware authentication. The downstream client code then uses the operator's NETLICENSING_API_KEY to authenticate upstream REST API calls, effectively granting unauthenticated attackers full access to MCP tools. This access allows enumeration of products, licenses, licensees, and transactions, as well as creation, modification, validation, and destructive deletion of licensing objects. The vulnerability affects HTTP deployments with server-side keys and requires no user interaction. The issue is resolved in version 0.1.6.

Potential Impact

An unauthenticated attacker can fully control the licensing management functions exposed by the MCP interface, including reading sensitive licensing data and performing destructive operations such as deleting licenses. This compromises confidentiality, integrity, and availability of the licensing system under the operator's account. The vulnerability has a CVSS 3.1 score of 8.1 (high severity), indicating network exploitable with high impact on confidentiality, integrity, and availability.

Mitigation Recommendations

Upgrade Labs64 NetLicensing-MCP to version 0.1.6 or later, where this authentication bypass vulnerability is fixed. Until upgrading, restrict network access to the /mcp endpoint to trusted users only, and avoid using HTTP transport without proper authentication. Patch status is confirmed fixed in 0.1.6.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-15T15:30:40.317Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aac242c55bf5e2cf5ad8ffb

Added to database: 09/17/2026, 17:32:28 UTC

Last enriched: 09/17/2026, 17:46:30 UTC

Last updated: 09/17/2026, 19:32:32 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses