Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Meta Ads MCP Authentication Bypass and Token Leakage

Meta Ads MCP server prior to version 1.0.109 failed to authenticate HTTP requests, allowing unauthenticated callers to invoke MCP tools and potentially obtain access tokens through error responses. The vulnerability was fixed in version 1.0.109.

Disclosed 7 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated network-reachable callers could invoke MCP tools and potentially obtain operator access tokens through serialized error responses

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48039