CRITICALNuGet

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network

CVE-2026-26118Published 6 months agoUpdated 5 days agoSource: OSV

Affected packages

  • @azure/mcp
  • Azure.Mcp2.0.0-beta.1 → 2.0.0-beta.17
  • msmcp-azure2.0.0b14 → 2.0.0b17

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.