CVE-2026-54446
Last modified
CVE-2026-54446 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication.
Description
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication. The downstream api_key_ctx in src/netlicensing_mcp/client.py then falls back to the operator's NETLICENSING_API_KEY and authenticates upstream NetLicensing REST API calls under the operator account. An unauthenticated attacker can invoke MCP tools to enumerate products, licenses, licensees, and transactions, create or modify licensing objects, perform validations, and execute destructive delete operations. The issue affects HTTP deployments configured with a server-side key and does not require user interaction. This issue is fixed in version 0.1.6.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Labs64 | NetLicensing-MCP | < 0.1.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54446?
How severe is CVE-2026-54446?
How do I fix CVE-2026-54446?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54432Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allow…4.7
- CVE-2026-54433In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, t…10
- CVE-2026-5444A heap buffer overflow vulnerability exists in the PAM image…7.1
- CVE-2026-54443Dashy is a self-hostable personal dashboard. From 1.9.4 unti…5.9
- CVE-2026-54444Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUM…
- CVE-2026-54445vantage6 is an open-source infrastructure for privacy preser…6.9
- CVE-2026-54447garminconnect is a Python 3 API wrapper for Garmin Connect t…8.4
- CVE-2026-54448Trivy is a security scanner. Prior to 0.71.0, when Trivy sca…6.5
- CVE-2026-54449LangBot is a global IM bot platform designed for LLMs. In ve…8.8
- CVE-2026-5445An out-of-bounds read vulnerability exists in the `DecodeLoo…9.1
- CVE-2026-54450ToolHive is a utility designed to simplify the deployment an…2.9
- CVE-2026-54451Elixir protobuf is a pure Elixir implementation of Google Pr…8.2
Are you affected by CVE-2026-54446?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
