Telnyx MCP Server Missing Authentication on HTTP Transport
The Telnyx MCP server exposed its HTTP transport on all interfaces without requiring authentication, allowing unauthenticated access to dispatch tools and the server's stored credentials including API keys and code-execution keys.
Disclosed 27 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated callers able to reach the exposed port could access the server's stored Telnyx API key, client secret, and code-execution key, and dispatch tools with these credentials.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-81098
