← Back to search

CVE-2026-51994

9.1 CRITICALpublic exploit available

Published 2026-09-24 · Updated 2026-09-25

AI risk analysis

Summary
The flaw allows an attacker to forge server-side requests, potentially leading to unauthorized access to internal resources via the WWW-Authenticate header.
Exploitability
Exploitation is moderately hard as it requires control over the remote MCP server's WWW-Authenticate header, but once achieved, can lead to full control over the affected system.
Blast radius
If exploited, the impact could be severe, as it allows unauthorized access to internal resources, potentially leading to data theft or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to mcp-remote version 0.1.39 or later.
ssrfauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-918

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.