MCPA-2026-0001
highssrfCVSS 8.8
Azure MCP Server server-side request forgery allows privilege elevation (CVE-2026-26118)
Server-Side Request Forgery (SSRF) in Microsoft's Azure MCP Server allows an authorized attacker to elevate privileges over a network. Affects the npm, NuGet and PyPI distributions of Azure MCP Server Tools.
Assigned CWE-918 (SSRF) by Microsoft. Affected: 1.x prior to 1.0.2 and 2.0.0 pre-releases prior to 2.0.0-beta.17 (npm @azure/mcp and NuGet Azure.Mcp); PyPI msmcp-azure 2.0.0b14 to before 2.0.0b17. Patched in 1.0.2 and 2.0.0-beta.17 (PyPI 2.0.0b17).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @azure/mcp | >= 1.0.0, < 1.0.2 >= 2.0.0-beta.1, < 2.0.0-beta.17 |
| nuget | Azure.Mcp | >= 1.0.0, < 1.0.2 >= 2.0.0-beta.1, < 2.0.0-beta.17 |
| pypi | msmcp-azure | >= 2.0.0b14, < 2.0.0b17 |
Identifiers
CVE-2026-26118GHSA-hhfx-wfvq-7g9cCWE-918
References
- vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118
- advisory https://nvd.nist.gov/vuln/detail/CVE-2026-26118
- advisory https://github.com/advisories/GHSA-hhfx-wfvq-7g9c
Timeline
- Published: 2026-03-10