CVE-2026-90474: MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass

Published Sep 12, 2026
·
Updated

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.

Affected Software

1 affected component
MCPHub<1.0.32

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MCPHub to a version that resolves this vulnerability.

    Fixed in 1.0.32
  2. Configuration

    Ensure client authentication is enabled (it is disabled by default in MCPHub versions before 1.0.32) so that client secrets are required for token redemption.

    MCPHub embedded OAuth 2.0 authorization server client authentication = enabled
  3. Configuration

    Enable/require PKCE enforcement (PKCE is optional in MCPHub versions before 1.0.32) to prevent redemption of an intercepted authorization code without the PKCE verifier.

    MCPHub embedded OAuth 2.0 authorization server PKCE enforcement = required

Event History

Sep 12, 2026
CVE Published
via MITRE·11:06 AM
Data Sourced
via MITRE·11:06 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed by default?

MCPHub versions before 1.0.32 are affected because embedded OAuth 2.0 client authentication is disabled by default and PKCE enforcement is optional.

2

What does an attacker need to exploit this issue?

An attacker must obtain an OAuth authorization code through interception. They can then redeem that code for an access token without a client secret or PKCE verifier.

3

What access can a successful attacker obtain?

A successful attacker can gain access to the victim account and the privileges associated with that account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203