CVE-2026-42856Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, session, origin, or token check, and dispatches them directly to the orchestrator's tool registry. The default bind address is 0.0.0.0. As a result, any party with network reachability to the service can enumerate and invoke privileged management tools. This vulnerability is fixed in 5.1.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-06-22)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-11: 1Mentions · 2026-06-22: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-05-11: 1Technical Details · 2026-06-22: 305-1106-22
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-111
Patch1
2026-06-223
Disclosure3
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 11, 2026, security researchers disclosed CVE-2026-42856: a critical missing-authentication vulnerability (CWE-306) in Network-AI versions prior to 5.1.3. The vulnerability lives in the MCP HTTP transport handler, which processes Model Context Protocol (MCP) requests…

    Post summary

    Researchers disclosed the CVE‑2026‑42856 missing‑authentication flaw in older Network‑AI versions, presenting technical details but no proof of concept, exploit, or remediation steps.

    1000026
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-42856: Network-AI MCP Transport Admits Unauthenticated Attackers—The Default Catastrophe Network-AI, a TypeScript/Node.js multi-agent orchestrator, ships with zero authentication on its MCP HTTP transport layer—prior to v5.1.3, anyone on the network can invoke…

    Post summary

    The post announces that Network‑AI’s MCP transport has no authentication before version 5.1.3, exposing the system to unauthenticated network attacks.

    1000034
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    3, anyone — CVE-2026-42856: Network-AI MCP Transport Admits Unauthenticated Attackers—The Default Catastrophe. Network-AI, a TypeScript/Node.js multi-agent orchestrator, ships with zero authentication on its MCP HTTP transport layer—prior to v5.1.3, anyone on the network…

    Post summary

    CVE‑2026‑42856 exposes unauthenticated access in Network‑AI’s MCP transport layer on versions prior to 5.1.3; while no PoC or exploit is shared, the vulnerability is disclosed with an implied patch version.

    1000031
    294 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-42856 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, sessi… https://www.cve.org/CVERecord?id=CVE-2026-42856

    Post summary

    CVE-2026-42856 allows unauthenticated JSON‑RPC calls on Network-AI’s MCP HTTP transport; the issue is mitigated by upgrading to version 5.1.3, with no PoC or active exploitation reported.

    0000071
    57.5K followersView on X

Explore more