Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
PoC: mcp-attack-detection-sentinel
Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation. Maps to OWASP Agentic Top 10. 5 analytics rules, 7 hunting queries, workbook. Companion to nineliveszerotrust.com.
PoC: mcp-check
MCP server security scanner — tests against clause-compliance vulnerabilities (arxiv 2603.10163), CVE-2026-26118, and common MCP security gaps
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free