Authentication enforced
Privileged tools require authentication and enforce it on every path, not just the documented one.
- Applies to
- MCP servers
- Standard references
- CWE-306
A finding here is not a failure
Software of any size carries something. A listing that raises findings on this check is still sold, with the findings published and their severity and reachability stated. A badge that only ever said pass would teach people to stop reading it.
Explainer · 2026-09-30
Authentication in MCP servers: when a local tool becomes a network service
A server that talks over stdio can only be reached by the program that started it. Switch the same server to HTTP and anyone who can reach the port can use it, with whatever credentials it holds.
What this row checks
That privileged tools require authentication and enforce it on every path, not just the documented one. A check that guards the main endpoint and forgets a second route is not a check.
Why the transport decides the question
Over stdio there is no endpoint to protect: the MCP specification says stdio implementations should not follow its authorisation flow and should take credentials from the environment instead. Over HTTP the specification describes authorisation based on OAuth 2.1, in which the server validates that every token it receives was issued for it. Its security guidance adds that a server meant to run locally should use stdio, or require an authorisation token if it uses HTTP.
What the hand run found
Two of the thirty servers read by hand had an optional network mode that listened on every network interface with no authentication at all, and acted with the operator's own credentials for the service behind it. One of them also allowed requests from any origin. Neither is a problem in the default stdio mode. Both turn into one the moment somebody switches the network mode on to share the tool.
Listening on 127.0.0.1 rather than on every interface would have limited either to the machine it runs on. Requiring a token would have limited it to the people meant to use it.
In the glossary: stdio transport, Streamable HTTP, Scoped credential.
What this check has found
2 listings in the catalogue raise a finding here. Every one is still sold, with the finding printed on its page.
- MCP Server Atlassian Confluence
Read by hand on 2026-09-30: The HTTP transport, switched on with TRANSPORT_MODE=http, listens on every network interface with open CORS and no authentication, and acts with the operator's Atlassian token. The default, stdio, is not affected.
- MCP Server Kubernetes
Read by hand on 2026-09-30: The SSE transport, switched on with ENABLE_UNSAFE_SSE_TRANSPORT, listens on every interface with no authentication. Its own comment calls it unsafe.
Every listing in the catalogue shows its result on this check, with the findings summarised in public and the full report to whoever bought it. Open the catalogue.