External risk intelligence

metatool-ai MetaMCP IDOR Allows Tenant Data Exfiltration and Tool Execution

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-79537

The vulnerability resides in an MCP transport session dispatch mechanism designed for remote service interaction. As an API or service-oriented component that handles multi-tenant sessions and tool execution, it is commonly deployed as an externally reachable web or API service to facilitate communication between AI agents and external resources.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in MetaMCP's session management, allowing unauthenticated attackers to impersonate other tenants. This could enable unauthorized access to and exfiltration of sensitive data by exploiting a weakness in how sessions are handled and authorized for specific endpoints. The main concern is confirming relevance and exposure.

  • Session flaws allow unauthorized access to tenant data.
  • Critical risk to data confidentiality and integrity.
  • Confirm impact on your multi-tenant AI services.

Attack Path

How an attacker could exploit the issue

An attacker can gain unauthorized access to another tenant's data and tools by exploiting an insecure direct object reference in the session management. This allows them to bypass authentication and authorization checks, ultimately leading to sensitive information disclosure and unauthorized execution of private tools.

  • Unauthenticated access to session IDs is required.
  • Mismatched session IDs trigger unauthorized access.
  • Sensitive data exposure and tool execution.

Live Threat

Current exploitation, exposure, and threat context

An attacker could gain unauthorized access to a victim tenant's private tools and data by exploiting a weakness in how session identifiers are handled. This could occur when the system improperly validates session IDs, allowing an attacker to impersonate a legitimate user to list and execute tools, and potentially exfiltrate data using the victim's credentials.

  • Private tools and data at risk.
  • Unauthenticated session ID disclosure.
  • Unauthorized access and data exfiltration.

Operational Fix

Recommended remediation, mitigation, and detection steps

The identified Insecure Direct Object Reference vulnerability in MetaMCP's session handling suggests that platform or application teams managing the MetaMCP deployment are the most likely owners. The first practical step is to identify all MetaMCP instances, determine their exposure and business criticality, and then confirm the accountable owner for each instance to prioritize remediation efforts.

  • Platform/Application teams own the issue.
  • Verify MetaMCP instance exposure and criticality.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is metatool-ai MetaMCP?

MetaMCP is a software component used to manage transport sessions within the Model Context Protocol (MCP). It acts as a bridge that allows AI agents to interact with external tools and resources. Developers typically integrate it into their AI platforms to enable these agents to execute specific tasks and retrieve data securely in multi-tenant environments.

What does CVE-2026-79537 mean?

This CVE refers to an Insecure Direct Object Reference (CWE-639) vulnerability. In MetaMCP, the session manager trusts the ID provided by a client without verifying if that user actually owns the session. Because the system lacks proper binding between a session and its owner, an attacker can substitute their own session ID with a victim's ID to gain unauthorized access.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by obtaining a valid session ID and namespace UUID, which are disclosed through the /metamcp/health/sessions endpoint. Simply sending a request to this endpoint is not the vulnerability itself, but it provides the necessary data to impersonate another tenant. The flaw is not triggered if the session ID used matches the attacker's own authenticated account.

Do I need to worry about this if my service is internal?

Halo Surface Signal indicates this component is often deployed as an externally reachable API to facilitate remote agent communication, increasing risk. However, if your MetaMCP deployment is strictly internal and has no network path to the outside world, the risk of unauthenticated external actors accessing your session management is significantly reduced.

How should I respond to this threat?

Your first step is to locate all active MetaMCP instances within your environment. Once identified, evaluate whether these services are exposed to untrusted networks. Coordinate with your platform and application teams to confirm ownership of these instances, assess the business sensitivity of the data they handle, and prepare for updates or configuration changes to secure the session management logic.

References