Junglewise Threat Intelligence

CVE-2026-49257: startreedata mcp-pinot Missing Authentication in HTTP MCP Server

CVE-2026-49257 · Severity: critical · CVSS 10 · Published 2026-06-18

Vendors: PyPI.

Executive brief

mcp-pinot is a server component used to interface with Apache Pinot clusters. In its default configuration, the server is accessible to anyone on the network without a password. An attacker can exploit this to read sensitive data, modify database schemas, or disrupt the availability of the connected Pinot cluster by using the server's own administrative credentials.

Technical details

The vulnerability arises from three default configuration settings: OAuth authentication is disabled by default, the HTTP server binds to 0.0.0.0 (all interfaces), and the server uses its own privileged Pinot credentials to execute requests from any caller. This creates a 'confused deputy' scenario where an unauthenticated network-adjacent attacker can invoke any of the 14 registered MCP tools. Impacted tools include 'read_query' for arbitrary data access and 'create_schema'/'update_table_config' for cluster mutation. The issue is fixed in version 3.1.0 by changing the default bind to 127.0.0.1 and requiring OAuth for non-loopback connections.

Affected products

  • StarTree mcp-pinot-server <= 3.0.1

Timeline

  • 2026-05-23: disclosed: Disclosed via GitHub Security Advisory
  • 2026-05-25: patched: Fixed in v3.1.0 and PR #95 merged
  • 2026-05-25: advisory: GitHub Advisory published

References