
Published our new research: CVE-2026-52870 (Missing Authorization) in @AnthropicAI's MCP Python SDK. On multi-client MCP servers, any authenticated client could enumerate and hijack tasks from other clients. Patched in v1.27.2. https://medium.com/@shrutilohani9/stealing-the-keys-to-the-agentic-cloud-critical-authorization-flaw-in-anthropics-mcp-sdk-6a4bb74bead2 @Shruti__Lohani
Post summary
A new authorization flaw (CVE-2026-52870) in Anthropic’s MCP Python SDK lets authenticated users enumerate and hijack tasks across clients; the issue has been patched in v1.27.2.


