A critical vulnerability, CVE-2026-52830(CVSS 9.4), has been identified in fast-mcp-telegram, an MCP (Model Context Protocol) server that enables Telegram integrations. The flaw affects all versions prior to 0.19.1 and allows unauthenticated remote attackers to bypass session authentication through improper validation of HTTP Bearer tokens. Successful exploitation can provide unauthorized access to the default Telegram session, exposing sensitive information and enabling misuse of Telegram-connected MCP services. The vulnerability stems from the application's authentication logic, which generates a session file path directly from the supplied Bearer token without adequately sanitizing or normalizing user input. While the reserved session name "telegram" is explicitly blocked, the application does not properly prevent directory traversal sequences such as `../`. By crafting a malicious Bearer token that references the default legacy session file, an attacker can force the application to load an existing session and authenticate without valid credentials. Because the attack requires no prior authentication and can be executed remotely over HTTP, internet-facing deployments are particularly vulnerable. The flaw bypasses authentication controls rather than stealing credentials, making it highly effective against exposed MCP servers. Organizations using fast-mcp-telegram should immediately upgrade to version 0.19.1 or later, restrict external access to MCP services, monitor authentication logs for suspicious requests, and validate session file security to mitigate the risk of unauthorized access.
Pro-Iran hacktivist groups have intensified cyber operations targeting critical infrastructure, government agencies, technology providers, and organizations perceived to support th...
Russian state-sponsored cyber actors are actively targeting vulnerable and poorly secured network routers to gain unauthorized access to organizations, particularly those operating...
A recent wire-level analysis conducted on Grok Build CLI version reported that the tool automatically transmitted complete Git repositories, including unread files and commit histo...