PatchSiren cyber security CVE debrief
CVE-2026-86122 rowboatlabs CVE debrief
CVE-2026-86122 is a server-side request forgery vulnerability in Rowboat through version 0.9.1. The vulnerability allows authenticated users to configure arbitrary destinations for custom MCP server and webhook URLs, which can be exploited to perform server-side request forgery and enumerate internal network topology. This issue is particularly concerning for defenders responsible for Rowboat deployments, especially in environments where internal network topology is sensitive. To address this vulnerability, defenders should assess exposure and prioritize verification of custom MCP server and webhook URL configurations.
- Vendor
- rowboatlabs
- Product
- rowboat
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-05
- Original CVE updated
- 2026-09-05
- Advisory published
- 2026-09-05
- Advisory updated
- 2026-09-05
Who should care
Defenders responsible for Rowboat deployments, especially in environments where internal network topology is sensitive, should assess exposure and prioritize verification of custom MCP server and webhook URL configurations.
Why it matters
CVE-2026-86122 is a server-side request forgery vulnerability in Rowboat through version 0.9.1 that allows authenticated users to configure arbitrary destinations for custom MCP server and webhook URLs, which can be exploited to perform server-side request forgery and enumerate internal network topology. Defenders should prioritize verifying the configuration of custom MCP server and webhook URLs in Rowboat deployments, especially in environments where internal network topology is sensitive.
- Enumeration of internal network topology
- Potential access to sensitive internal services
- Risk of server-side request forgery attacks
- Need for verification of custom MCP server and webhook URL configurations
Technical summary
The vulnerability in Rowboat through version 0.9.1 allows authenticated users to configure arbitrary destinations for custom MCP server and webhook URLs. This can be exploited to perform server-side request forgery and enumerate internal network topology. The issue arises from inadequate validation of custom MCP server and webhook URLs, enabling attackers to point these URLs at internal services and cloud metadata endpoints. To mitigate this vulnerability, defenders should verify the configuration of custom MCP server and webhook URLs in Rowboat deployments, especially in sensitive environments, and consider restricting the configuration to trusted users and destinations. Additionally, monitoring Rowboat logs for suspicious activity related to custom MCP server and webhook URLs can help detect potential attacks. Affected deployments should be reviewed for exposure, and compensating controls should be considered while remediation is scheduled and verified. The CVE record and NVD entry provide details on the vulnerability, but further verification is required to establish versions beyond 0.9.1, exploitation, impact, or remediation. Official sources should be consulted for the most accurate and up-to-date information. Consider upgrading to a version of Rowboat that addresses this vulnerability, if available, and track exceptions, retest remediated assets, and close the item only after evidence is documented. The configuration of custom MCP server and webhook URLs should be restricted to trusted users and destinations to prevent unauthorized access. Monitoring and detection capabilities should be reviewed to ensure they can identify suspicious activity related to custom MCP server and webhook URLs. Asset inventory and rollback/change windows should also be considered as part of the remediation process. Source tracking and verification are crucial in ensuring the accuracy of the information and the effectiveness of the remediation efforts. Compensating controls, such as additional monitoring or access controls, may be necessary for exposed systems while remediation is scheduled and verified. The vulnerability highlights the importance of verifying the configuration
Defensive priority
Defenders should prioritize verifying the configuration of custom MCP server and webhook URLs in Rowboat deployments, especially in environments where internal network topology is sensitive.
Recommended defensive actions
- Verify the configuration of custom MCP server and webhook URLs in Rowboat deployments.
- Restrict the configuration of custom MCP server and webhook URLs to trusted users and destinations.
- Monitor Rowboat logs for suspicious activity related to custom MCP server and webhook URLs.
- Consider upgrading to a version of Rowboat that addresses this vulnerability, if available.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score. However, the corpus does not establish versions beyond 0.9.1, exploitation, impact, or remediation, which require verification from the supplied official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/rowboatlabs/rowboat
-
Source reference
Unverified legacy reference
URL: https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/lib/agents-runtime/agent-tools.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/use-cases/projects/add-custom-mcp-server.use-case.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/rowboatlabs/rowboat/issues/621
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/rowboat-through-0.9.1-server-side-request-forgery-via-custom-mcp-server
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.