Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Network-AI MCP SSE server unauthenticated by default (CVE-2026-48814)

Network-AI, a TypeScript/Node.js multi-agent orchestrator, shipped an MCP SSE server with an empty default secret through version 5.7.1, so its authorization check passed for any caller. Non-browser clients such as curl or SSRF requests could invoke all 22 MCP tools (including config_set, agent_spawn and blackboard_write) without credentials; fixed in version 5.7.2.

Disclosed 17 June 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers could invoke all 22 MCP tools on affected servers, including configuration changes, agent spawning and blackboard writes.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48814