SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-55637

HIGH · CVSS 8.8 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Streamable HTTP transport in GenieACS prior to version 0.3.2 is vulnerable due to an unauthenticated listener on the loopback address, which can be exploited via DNS rebinding attacks. This allows attackers to initialize an MCP session and manipulate critical device management functions, potentially leading to unauthorized access or modification of CPE management states. Organizations using affected versions of GenieACS should prioritize upgrading to version 0.3.2 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55637
Severity
HIGH
CVSS
8.8
EPSS
0.21%

Original NVD Description

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKEN is unset and the httpSrv.Start(addr) branch does not validate the Host or Origin headers. A malicious website can use DNS rebinding to send browser requests with attacker-controlled Host and Origin values to the loopback listener, initialize an MCP session, list tools, and invoke operations against the GenieACS NBI configured by ACS_URL. Successful exploitation can expose or modify CPE management state, including device reboots, firmware tasks, TR-069 parameter changes, presets, provisions, tags, connection requests, and task operations. The npm wrapper is not affected because it forces TRANSPORT=stdio and does not expose an HTTP listener. This issue is fixed in version 0.3.2.