CVE-2026-32585: WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerability
Published Oct 2, 2026
·Updated
Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through 2.11.0.
Affected Software
1 affected component
Airano Airano MCP Bridge<=2.11.0
Event History
Oct 2, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is network-accessible and requires an attacker to have low-privileged access. No user interaction is required.
2
What is the likely impact if it is exploited?
The provided CVSS vector indicates an integrity impact, with no stated confidentiality or availability impact. The issue involves incorrectly configured access-control levels.
3
Which versions are affected?
Airano MCP Bridge versions through 2.11.0 are affected. The available data does not identify a fixed version.