Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Network-AI MCP SSE Server Missing Authentication

Network-AI versions prior to 5.4.5 have an MCP SSE server that defaults to empty authentication and allows CORS, enabling unauthenticated attackers to invoke all 22 exposed MCP tools via cross-origin requests.

Disclosed 20 July 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can invoke all 22 exposed MCP tools including config_set, agent_spawn, and blackboard_write against default-configured localhost servers via malicious web pages.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-46701