# MCPHub auth bypass lets attackers hijack user privileges

Published: 2026-04-14 · Severity: medium
Canonical: https://vorant.io/reports/9e159839-86f0-5617-b2b2-5a73c37e0554/mcphub-auth-bypass-lets-attackers-hijack-user-privileges

> MCPHub versions below 0.11.0 contain an authentication bypass flaw (CVE-2025-13822) allowing unauthenticated attackers to impersonate users and abuse their privileges.

CERT Polska disclosed CVE-2025-13822, an authentication bypass vulnerability in MCPHub affecting all versions prior to 0.11.0. The flaw stems from endpoints that lack authentication middleware protection, enabling unauthenticated attackers to execute actions as legitimate users and leverage their privileges without proper authorization checks.

The vulnerability was responsibly reported by Eryk Winiarz and coordinated through CERT Polska's disclosure process. Organizations running affected MCPHub versions should upgrade to 0.11.0 or later to remediate the issue. The advisory provides minimal technical detail beyond the authentication bypass mechanism, and there is no indication of active exploitation at the time of disclosure.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13822

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2025-13822

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9e159839-86f0-5617-b2b2-5a73c37e0554/mcphub-auth-bypass-lets-attackers-hijack-user-privileges.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
