CVE-2026-19268Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3PoC Mentioned / Linked · 2026-08-08: 1Technical Details · 2026-08-08: 308-08
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19268 A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file sr… https://www.cve.org/CVERecord?id=CVE-2026-19268 ----- Traducción: Se identificó una … http://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE-2026-19268 in the abdullah1854 MCPGateway project, noting the affected function and linking to the CVE record, but provides no exploit, patch, or additional technical details.

    0000029
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19268 A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file sr… https://www.cve.org/CVERecord?id=CVE-2026-19268

    Post summary

    CVE-2026-19268 has been identified in abdullah1854 MCPGateway, affecting the getUsageByDateRange function; no exploit, patch, or active exploitation information is provided.

    00000848
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    PoC

    🚨 MCPGateway command injection remotely reachable CVE-2026-19268 A flaw in MCPGateway's Claude usage endpoint allows manipulation of the since parameter to trigger command injection. 🌐 The attack can be initiated remotely. ⚠️ A public exploit has been disclosed. 🔎 Source: Rapid7 / MITRE CVE #MCP #Claude #CommandInjection #CyberSecurity #CVE

    Post summary

    The tweet announces that a command injection flaw (CVE-2026-19268) in MCPGateway’s Claude usage endpoint can be triggered remotely and that a public exploit has been disclosed.

    0000044
    34 followersView on X

Explore more