New vulnerability in 1MCP Agent allows already authenticated users to bypass token-based OAuth access restrictions. The flaw affects versions 0.20.0 through 0.39.0 and could expose tools on connected MCP servers beyond the privileges granted by a token.

The issue does not allow login without an account by itself. It affects customers who have a valid token with limited access and use the 1MCP Agent as a single point of connection to tool servers. The workaround may, however, override the isolation designed for different groups or access levels.
How bypass works in 1MCP Agent
According to VulnCheck's technical description, the error occurs when the authorization check processes a label filter with a deny. For example, a token may allow the label "internal" while the request asks for "not internal."
In 1MCP Agent, the check examines the label referenced in the expression, rather than applying the final filter result within the bounds of the granted permissions. Thus, an expression that includes a permitted label may pass the check, even though it ultimately selects servers that do not have that label.
The research analysis describes a function-level test where the denial allowed a server selection outside the allowed set. The same analysis clarifies that full testing was not done using a real HTTP connection, OAuth token, and live servers; this limitation should not be overlooked when evaluating the proof.

Which facilities are affected?
The National Vulnerability Database entry CVE-2026-108586 covers 1MCP Agent versions 0.20.0 through 0.39.0. VulnCheck rates the vulnerability at 5.3 on the CVSS 4.0 scale, a medium severity level, and classifies it as an incorrect authorization vulnerability. This is not an authentication bypass.
For the vulnerability to be effective, the user must already be authenticated and have a token with at least one specific label. The installation must also use labels as access limits and have tool servers with different labels. If any of these elements are missing, the specific requirements of the bypass are not met.
In a multi-team environment, the override could broaden visibility to tools intended for a different set of users. In a 1MCP Agent installation, it could expose higher-privileged tools to accounts with a limited role. The actual impact depends on each organization's connections and tagging policy.
The issue is primarily about limiting access to tools, not a blanket breach of all MCP servers. Administrators need to check which tools are connected, what tags are being used, and whether customers are relying solely on them to isolate accounts or data.
See also: MCP Python SDK: Stealing OAuth credentials from malicious servers

The researcher's analysis of the 1MCP Agent also presents test examples with filters such as "!internal" and "-internal", which result in the same denial logic. It does not document any exploitation incidents in real installations or confirm that attackers have used the vulnerability; such a conclusion does not emerge from the available sources.
No published patch is found in the available listings. The project's releases page shows 0.39.0 as the latest version, which is within the range reported as vulnerable. The project's security notices page does not show a published related notice.
The researcher suggests as a technical workaround to limit any filter results to the labels given in the token and to double-check authorization when running tools. These are analysis suggestions, not an official guideline or confirmed fix by the project team.
What can administrators do now?
Until a fix is announced, the SecNews technical team recommends that administrators not treat OAuth tokens as a single isolation barrier. They can temporarily reduce the tools available, restrict access at the network level, and review the permissions of tokens that have already been issued.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: SiYuan vulnerability exposed document metadata
It is also useful to check logs for requests with negative filters and for tool calls that do not match the expected role of each client. These checks do not prove exploitation in themselves, but can help identify unusual access and review rules.
Organizations using the 1MCP Agent need to monitor the official project releases and confirm that any subsequent release explicitly mentions the fix for CVE-2026-108586. Upgrading to a version that is still within the stated scope is not sufficient proof of resolution.
CVE-2026-108586 highlights the importance of checking complex filter expressions for their final result, not just their individual components. For organizations using the 1MCP Agent, access to connected tools should also be protected with independent authorization checks until a clear fix is confirmed.
See also: ezBookkeeping flaw turned API token into session
