CVE-2026-58446: Presenton MCP endpoint bypasses session authentication
Presenton before 0.8.8-beta exposed its bundled MCP server unauthenticated at /mcp because the nginx front-end did not apply the auth_request gate and the MCP server auto-minted a valid internal session token. Remote unauthenticated attackers could invoke MCP tools such as generate_presentation, consuming the operator's LLM API keys and creating presentations in their instance.
Disclosed 30 June 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated attackers could perform authenticated application actions via MCP tools, consume the operator's configured LLM API keys and create presentations in the operator's instance. Server/Docker deployments using session authentication were affected; the Electron desktop build was not.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-58446
