THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture

[NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture

mednvdPublished 2026-08-25

CVE-2026-79786 CVSS: 7.1 HIGH Published: 2026-08-25T19:16:54.750

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79786