LangBot MCP Server RCE via Insufficient Authorization
LangBot versions 4.10.7 and earlier allow authenticated users to execute arbitrary commands on the server by configuring STDIO MCP servers without proper authorization checks. An attacker with an account can achieve remote code execution with service privileges.
Disclosed 20 August 2026 · Record updated 13 September 2026
Impact
Arbitrary command execution with LangBot service privileges, enabling data disclosure, modification, and service disruption
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54449
