https://reddit.com/r/cybersecurity/comments/1uheh0s/cve202652870_anthropic_mcp_python_sdk_missing/: CVE-2026-52870: Anthropic MCP Python SDK Missing Authorization Flaw
Published Jun 27, 2026
·Updated
Affected Software
1 affected component
Anthropic Model Context Protocol Python SDK (mcp)<1.27.2
Frequently Asked Questions
1
What is the severity of CVE-2026-52870?
CVE-2026-52870 is classified as a high severity vulnerability due to its potential to allow unauthorized access to client tasks.
2
How do I fix CVE-2026-52870?
To fix CVE-2026-52870, implement proper authorization checks in the request handlers of the Anthropic MCP Python SDK.
3
What type of vulnerability is CVE-2026-52870?
CVE-2026-52870 is a missing authorization flaw categorized under CWE-862.
4
Who is affected by CVE-2026-52870?
Any client using the Anthropic MCP Python SDK on a shared server is potentially affected by CVE-2026-52870.
5
What can attackers do with CVE-2026-52870?
Attackers can enumerate, read, and cancel tasks belonging to other clients on the same server due to CVE-2026-52870.