CVE-2026-50287 Details
Description
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and call tools directly. This issue has been patched in version 0.9.27.
A vulnerability exists in AgenticMail's @agenticmail/mcp package, prior to version 0.9.27, where the Streamable HTTP transport can be enabled without proper authentication. When the server is started with the --http option or MCP_HTTP=1, the /mcp endpoint accepts requests without any HTTP authentication. This allows remote clients to initialize a session and directly invoke tools, including those requiring the AGENTICMAIL_MASTER_KEY, by exploiting the server's configured master key.
Users are advised to update to AgenticMail version 0.9.27 or later, and to ensure that the MCP HTTP server requires authentication and is not exposed to the public.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/agenticmail/agenticmail/security/advisories/GHSA-63gr-g7jc-v8rg | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/agenticmail/agenticmail/security/advisories/GHSA-63gr-g7jc-v8rg | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AgenticMail MCP | < 0.9.27 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion