Back

CRITICAL

Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Transport

Published Aug 27, 2026

Description

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch forwarded the server's own stored credentials, the Telnyx API key and client secret together with the code-execution key, to the upstream endpoint, so an unauthenticated caller able to reach the port acted with them. The current code defaults the host to loopback, requires a server API key, and enforces it in middleware.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 27, 2026
Updated Aug 29, 2026
Reserved Aug 26, 2026
CISA Vulnrichment
Updated Aug 27, 2026
NVD
Status Received
Modified Aug 27, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 27, 2026
Updated Aug 29, 2026
Exploited since n/a
EUVD-2026-67026