HIGH
GeiserX
CVE published 2026-08-25
CVE-2026-55637
CVE-2026-55637 is a vulnerability in the genieacs-mcp MCP server for GenieACS, written in Go. The vulnerability allows an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKEN is unset. A malicious website can use DNS rebinding to send browser requests with attacker-controlled Host and Origin values to the loopback listener, initialize an MCP session, list t [truncated]