40% of MCP Servers Expose Tools Without Authentication
Key point
A scan of live MCP servers in operation found that about 40% expose tools without any authentication process, revealing a security vulnerability.
Details
A measurement study conducted on approximately 8,000 live MCP (Model Context Protocol) servers found that 40.55% of the total were exposing tools without any authentication at all. This goes beyond simple misconfiguration—it is a serious security flaw where authentication itself was never implemented.
The key research findings are as follows:
- Lack of Authentication: A significant number of the scanned servers were exposing sensitive information, such as internal CRM data, without authentication.
- OAuth Vulnerabilities: When testing servers that use OAuth, at least one authentication flaw was found in all 119 servers tested.
- Dynamic Client Registration Issues: Security issues related to Dynamic Client Registration occurred in 96.6% of the servers tested.
The research points to a gap between simply following the spec and actually verifying the implementation. Even when settings like PKCE are enabled, it is essential to periodically test and verify that they actually work under real attack conditions (such as redirect URI bypass and code reuse).
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.