CVE-2026-108586
Received Received - Intake

Incorrect Authorization in 1MCP Agent via Negated Tag-Filter Bypass

Vulnerability report for CVE-2026-108586, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

1MCP Agent (@1mcp/agent) 0.20.0 through 0.39.0 contains an incorrect authorization vulnerability that allows authenticated clients to bypass OAuth tag-scope enforcement using negated advanced tag-filter expressions. Attackers holding a single-tag token can send a filter like not <granted-tag> to list and invoke tools on backend MCP servers outside their granted scopes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
1mcp-app @1mcp/agent 0.20.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108586 is an incorrect authorization vulnerability in 1MCP Agent versions 0.20.0 through 0.39.0. It allows authenticated clients with a single-tag OAuth token to bypass scope restrictions using negated tag-filter expressions like 'not <granted-tag>'. The authorization layer checks only the tags in the filter but not the final result, letting attackers access servers outside their granted scopes by selecting all backends not matching the granted tag.

Detection Guidance

To detect this vulnerability, inspect HTTP requests to 1MCP Agent endpoints for negated tag-filter expressions like 'not internal' in the 'tag-filter' parameter. Check if authenticated clients with single-tag tokens can access tools outside their granted scopes. Review logs for requests bypassing OAuth scope validation.

Impact Analysis

This vulnerability enables attackers to list and invoke tools on backend MCP servers outside their authorized scopes. In multi-tenant setups, it could lead to cross-tenant data access. In single-tenant environments with tiered access, it may allow privilege escalation by accessing higher-privilege tools or data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR and HIPAA. GDPR mandates strict access controls and data protection, while HIPAA requires safeguards to prevent unauthorized disclosure of protected health information. The flaw allows attackers to bypass OAuth tag-scope enforcement, potentially exposing out-of-scope servers and their tools.

Mitigation Strategies

Upgrade 1MCP Agent to a patched version beyond 0.39.0. Implement middleware to intersect advanced filter results with granted tags. Disable negated tag-filter expressions in OAuth scope validation. Monitor for unauthorized access attempts using negated filters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108586. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart