CVE-2026-58446: Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp becau...

Added to the CISA Known Exploited Vulnerabilities catalog on 30 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end does not apply the auth_request gate to that path and the MCP server auto-min...

Required action: Review and patch if applicable to your AI infrastructure.