{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/coroot/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-79786"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["coroot"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Coroot"],"content_html":"\u003cp\u003eCoroot, an open-source observability tool, contains a critical vulnerability (CVE-2026-79786) in its MCP (Machine Configuration Profile) OAuth dynamic client registration endpoint. This endpoint does not perform validation on the redirect URI provided during the client registration process, allowing an unauthenticated attacker to register an arbitrary redirect URI. By sending a crafted authorization URL to a legitimate user, an attacker can trick the user into consenting to access. Upon approval, the application redirects the user's authorization code to an attacker-controlled server. The attacker can then exchange this code for an access token, enabling full session hijacking of the user's MCP session. This vulnerability affects Coroot versions 1.20.2 through 1.24.5.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the unauthenticated MCP OAuth dynamic client registration endpoint in the target Coroot instance.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP request to the registration endpoint containing an arbitrary, attacker-controlled redirect URI.\u003c/li\u003e\n\u003cli\u003eThe Coroot application registers the malicious client and returns a client identifier to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious authorization URL using the obtained client identifier and sends it to a logged-in victim via social engineering.\u003c/li\u003e\n\u003cli\u003eVictim clicks the URL and is presented with an OAuth consent screen within the Coroot interface.\u003c/li\u003e\n\u003cli\u003eVictim approves the request, causing the Coroot server to redirect the victim's browser to the attacker-controlled URI with the valid authorization code in the query parameters.\u003c/li\u003e\n\u003cli\u003eAttacker captures the authorization code from their server logs.\u003c/li\u003e\n\u003cli\u003eAttacker exchanges the authorization code for an access token to gain unauthorized access to the victim's MCP session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized access to the victim's MCP sessions. This allows attackers to potentially modify monitoring configurations, access sensitive observability data, or move laterally within the infrastructure monitored by Coroot.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Coroot to a version beyond 1.24.5 immediately to remediate CVE-2026-79786.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for POST requests to the MCP OAuth registration endpoint originating from unauthorized or external IP ranges.\u003c/li\u003e\n\u003cli\u003eAudit existing OAuth client registrations for suspicious redirect URIs pointing to unknown or external domains.\u003c/li\u003e\n\u003cli\u003eRestrict access to internal management interfaces to trusted networks to reduce the surface area for unauthenticated API exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T20:49:23Z","date_published":"2026-08-25T20:49:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-coroot-mcp-oauth-hijack/","summary":"Coroot versions 1.20.2 through 1.24.5 are vulnerable to unauthenticated OAuth dynamic client registration, allowing attackers to hijack user sessions via open redirect and authorization code theft.","title":"Unauthenticated OAuth Client Registration in Coroot","url":"https://feed.craftedsignal.io/briefs/2026-08-coroot-mcp-oauth-hijack/"}],"language":"en","title":"CraftedSignal Threat Feed - Coroot","version":"https://jsonfeed.org/version/1.1"}