Threat Advisory

GenieACS MCP Vulnerability Skips Host Source Validation Grants Ability to CPE Functions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A high severity vulnerability CVE-2026-55637 with a CVSS score of 8.8 in genieacs-mcp exposes local Streamable HTTP transport to DNS rebinding attacks, allowing attacker-controlled Host and Origin headers to reach the MCP handler and invoke tools against the configured GenieACS backend without a browser-supplied secret, resulting in unauthorized access to sensitive data and potential business disruption. The vulnerability arises from the server accepting attacker-controlled Host and Origin values without validation, enabling a malicious web page to route browser requests to a victim's loopback MCP listener while preserving the attacker origin. This allows an attacker to bypass authentication and gain unauthorized access to GenieACS tools and data, posing a significant threat to the security of the system.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A high severity vulnerability CVE-2026-55637 with a CVSS score of 8.8 in genieacs-mcp exposes local Streamable HTTP transport to DNS rebinding attacks, allowing attacker-controlled Host and Origin headers to reach the MCP handler and invoke tools against the configured GenieACS backend without a browser-supplied secret, resulting in unauthorized access to sensitive data and potential business disruption. The vulnerability arises from the server accepting attacker-controlled Host and Origin values without validation, enabling a malicious web page to route browser requests to a victim's loopback MCP listener while preserving the attacker origin. This allows an attacker to bypass authentication and gain unauthorized access to GenieACS tools and data, posing a significant threat to the security of the system.[emaillocker id="1283"]

 

RECOMMENDATIONS:

  • We recommend you to update github.com/geiserx/genieacs-mcp to version 0.3.3 or later.


REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-cmwv-wf9p-p8wx

[/emaillocker]
crossmenu