THREAT OPS › Threat News › [NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture
[NVD] CVE-2026-79786 (HIGH 7.1) — Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture
CVE-2026-79786 CVSS: 7.1 HIGH Published: 2026-08-25T19:16:54.750
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent approval, and
Indicators of compromise
- CVE-2026-79786cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79786