MCPHub before 1.0.32 lets an intercepted OAuth authorization code be redeemed for tokens
NVD·high signal
CVE-2026-90474, published 2026-09-12 at CVSS 7.6, is an authentication bypass in MCPHub's embedded OAuth 2.0 authorization server: client authentication is off by default and PKCE enforcement is optional, so an attacker who intercepts an authorization code can redeem it for access tokens. It lands two days after the IBM Langflow and ContextForge cluster, and the pattern is the same, an MCP aggregation layer shipping permissive defaults.