PatchSiren cyber security CVE debrief
CVE-2026-35568 modelcontextprotocol CVE debrief
The CVE-2026-35568 vulnerability is a DNS rebinding issue in the MCP Java SDK prior to version 1.0.0. This vulnerability allows an attacker to access a locally or network-private MCP server via a victim's browser that is either local or network adjacent. Consequently, the attacker can make any tool calls to the server as if they were a locally running MCP connected AI agent. The vulnerability is fixed in version 1.0.0 of the MCP Java SDK.
- Vendor
- modelcontextprotocol
- Product
- java-sdk
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Organizations using the MCP Java SDK prior to version 1.0.0 should be aware of this vulnerability. Specifically, those with MCP servers that are locally or network-privately accessible may be at risk. Developers and administrators responsible for the MCP Java SDK and its deployments should take immediate action to update to version 1.0.0 or apply appropriate mitigations.
Technical summary
The MCP Java SDK, which is the official Java SDK for Model Context Protocol servers and clients, contains a DNS rebinding vulnerability prior to version 1.0.0. This vulnerability, identified as CVE-2026-35568, can be exploited by an attacker to access a locally or network-private MCP server through a victim's browser. The attacker can then make tool calls to the server as if they were a locally running MCP connected AI agent. The vulnerability is addressed and fixed in version 1.0.0 of the MCP Java SDK.
Defensive priority
High
Recommended defensive actions
- Update the MCP Java SDK to version 1.0.0 or later
- Review and restrict access to MCP servers to only necessary personnel and systems
- Implement network security measures to prevent unauthorized access to MCP servers
- Monitor for any suspicious activity related to MCP server interactions
- Perform a thorough inventory of assets using the MCP Java SDK to identify potential exposure
- Establish a change management process to ensure timely application of security patches
- Review and update incident response plans to include procedures for responding to potential exploitation of the MCP Java SDK vulnerability
Evidence notes
The CVE-2026-35568 vulnerability is confirmed to exist in the MCP Java SDK prior to version 1.0.0. The vulnerability allows for DNS rebinding attacks, enabling attackers to interact with local or network-private MCP servers. The fix in version 1.0.0 is confirmed. However, specific details about the exploitation and additional attack vectors are not provided in the available sources.
Official resources
-
CVE-2026-35568 CVE record
CVE.org
-
CVE-2026-35568 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T22:16:23.433Z and has not been modified since then. The NVD entry is currently Analyzed.