CVE-2026-50287: AgenticMail MCP server HTTP endpoint lacks authentication
Prior to version 0.9.27, the @agenticmail/mcp package exposed a Streamable HTTP transport (via --http or MCP_HTTP=1) whose /mcp endpoint accepted requests with no HTTP authentication, letting any remote client initialize a session and invoke tools directly. The issue was patched in version 0.9.27.
Disclosed 12 June 2026 · Record updated 13 September 2026
Impact
Unauthenticated remote clients could initialize an MCP session and call tools on the server, which provisions real email addresses and phone numbers for AI agents.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-50287
