#CVE202649257
startreedata mcp-pinot <=3.0.1: CRITICAL vuln (CVE-2026-49257) lets anyone access Pinot clusters — no auth on MCP server. Upgrade to 3.1.0 immediately. https://radar.offseq.com/threat/cve-2026-49257-cwe-306-missing-authentication-for--c0c28b77341e3a12 #OffSeq #Security #CVE202649257
CVE-2026-49257: CWE-306: Missing Authentication for Critical Function in startre
mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP t
radar.offseq.com
June 18, 2026 at 9:30 PM