{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dynatrace-mcp-server-v1.8.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dynatrace-mcp-server (v1.8.5)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","mcp","dynatrace","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Dynatrace"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@dynatrace-oss/dynatrace-mcp-server\u003c/code\u003e package, specifically version 1.8.5, contains a critical security vulnerability arising from its implementation of the HTTP transport mode. When the server is initialized with the \u003ccode\u003e--http\u003c/code\u003e flag, it creates a \u003ccode\u003eStreamableHTTPServerTransport\u003c/code\u003e that fails to implement any form of authentication, session validation, or host/origin verification. Consequently, the server accepts raw JSON-RPC \u003ccode\u003etools/call\u003c/code\u003e requests from any network-reachable source without requiring an \u003ccode\u003eAuthorization\u003c/code\u003e header.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary Model Context Protocol (MCP) tools under the context of the configured Dynatrace credentials. High-impact tools such as \u003ccode\u003eexecute_dql\u003c/code\u003e allow for the exfiltration of sensitive observability data, including logs, security events, and user session information. Additionally, the \u003ccode\u003ecreate_dynatrace_notebook\u003c/code\u003e tool permits unauthorized modification of tenant data. Deployments utilizing \u003ccode\u003e--host 0.0.0.0\u003c/code\u003e are particularly susceptible, as the vulnerability is exposed to all network interfaces.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a reachable \u003ccode\u003edynatrace-mcp-server\u003c/code\u003e instance listening on the configured HTTP port (e.g., 3999).\u003c/li\u003e\n\u003cli\u003eAttacker probes the endpoint with a JSON-RPC request to confirm the server is running in \u003ccode\u003e--http\u003c/code\u003e mode.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious \u003ccode\u003etools/call\u003c/code\u003e JSON-RPC payload targeting high-impact functionality such as \u003ccode\u003eexecute_dql\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the payload via an HTTP POST request to the server root, omitting any \u003ccode\u003eAuthorization\u003c/code\u003e or \u003ccode\u003eBearer\u003c/code\u003e token headers.\u003c/li\u003e\n\u003cli\u003eThe server's \u003ccode\u003eStreamableHTTPServerTransport\u003c/code\u003e handler parses the request body and executes the function call using the server's pre-configured \u003ccode\u003eDT_PLATFORM_TOKEN\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eexecute_dql\u003c/code\u003e tool executes the attacker-supplied DQL query against the Dynatrace environment.\u003c/li\u003e\n\u003cli\u003eResults from the query are returned directly to the attacker in the HTTP response body, facilitating unauthorized data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability represents a complete bypass of authentication for sensitive observability functions. Organizations running this server in containerized environments or on multi-tenant networks are at high risk. Successful exploitation grants attackers the ability to query logs, security events, and user metadata, as well as the ability to inject malicious or unauthorized notebook content into the Dynatrace tenant. Given the lack of required interaction and the sensitivity of the data involved, this flaw provides a direct path for data exfiltration and integrity compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to the \u003ccode\u003edynatrace-mcp-server\u003c/code\u003e HTTP port via firewall rules to ensure it is not reachable from untrusted networks.\u003c/li\u003e\n\u003cli\u003eUpdate to the latest version of \u003ccode\u003edynatrace-mcp-server\u003c/code\u003e or apply the manual remediation provided in the source which implements a timing-safe bearer token validation check for HTTP requests.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect inbound HTTP requests targeting the \u003ccode\u003e/\u003c/code\u003e endpoint that lack \u003ccode\u003eAuthorization\u003c/code\u003e headers.\u003c/li\u003e\n\u003cli\u003eMonitor webserver/proxy logs for suspicious POST requests to the MCP server endpoint, particularly those involving \u003ccode\u003eexecute_dql\u003c/code\u003e or \u003ccode\u003ecreate_dynatrace_notebook\u003c/code\u003e in the JSON-RPC method or parameter fields.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:30:34Z","date_published":"2026-07-31T19:30:34Z","id":"https://feed.craftedsignal.io/briefs/2026-07-dynatrace-mcp-unauth-access/","summary":"The dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.","title":"Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport","url":"https://feed.craftedsignal.io/briefs/2026-07-dynatrace-mcp-unauth-access/"}],"language":"en","title":"CraftedSignal Threat Feed - Dynatrace-Mcp-Server (V1.8.5)","version":"https://jsonfeed.org/version/1.1"}