Meta Ads MCP Authentication Bypass and Token Leakage
Meta Ads MCP server prior to version 1.0.109 failed to authenticate HTTP requests, allowing unauthenticated callers to invoke MCP tools and potentially obtain access tokens through error responses. The vulnerability was fixed in version 1.0.109.
Disclosed 7 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated network-reachable callers could invoke MCP tools and potentially obtain operator access tokens through serialized error responses
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48039
