CVE-2026-79537 Details
Description
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.
A cross-tenant session hijack vulnerability has been identified in metatool-ai MetaMCP versions through 2.4.22. The issue arises from an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store is keyed only by the client-supplied mcp-session-id header, without any owner, namespace, or endpoint binding. This flaw allows an attacker to exploit another tenant's session ID, obtained without authentication from the health sessions endpoint, to access and execute private MCP tools of the victim tenant, exfiltrating data using the victim's credentials.
As of now, no patched release has been identified. Until a patch is available, it is advised to restrict public access, limit deployments to trusted networks, require authentication on the session-listing health endpoint, and not run endpoints with authentication disabled on a reachable network.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/metatool-ai/metamcp | [email protected] | Source CodeVendor |
| https://www.traceforce.ai/security-advisories/cve-2026-79537 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| metatool-ai MetaMCP | <v2.4.22 (semver) >= 2.4.22, <= 2.4.22.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion