CVE-2026-79745: MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate end
Summary
MCPHub is a system that manages multiple MCP servers (APIs that handle specific tasks) and routes requests to them. Before version 1.0.32, the software had a security flaw where non-admin users could create or modify global prompt templates and resources (stored instructions shared across all users) because the system didn't check user permissions. This allowed attackers to inject malicious prompts (hidden instructions in input) that would affect other users' AI sessions.
Solution / Mitigation
This issue has been patched in version 1.0.32.
Vulnerability Details
7.1(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
network
low
low
none
August 31, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79745
First tracked: August 31, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%