
CVE-2026-79786 Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to registe… https://www.cve.org/CVERecord?id=CVE-2026-79786
Post summary
The CVE reveals that Coroot’s MCP OAuth dynamic client registration endpoint lacks redirect URI validation, potentially allowing attackers to register arbitrary redirect URIs.

