40% of MCP Servers Exposed Without Authentication, All OAuth Servers Vulnerable
·2026.09.22 08:17
Key point
40.55% of remote MCP servers are exposed without authentication, and all servers implementing OAuth have at least one security flaw.
Details
A recent measurement study of approximately 8,000 live remote MCP servers found that 40.55% of servers expose tools without authentication.
Servers implementing authentication (OAuth) were confirmed to have at least one security flaw, and over 300 CVEs have already been reported targeting MCP infrastructure.
Key Issues
- All MCP servers act as an identity issuer determining agent access permissions
- Most servers are not designed to securely handle these security requirements
- High likelihood that security configurations are not properly implemented when operating MCP servers in production environments
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.