Internet-exposed Model Context Protocol (MCP) servers are frequently running without authentication, allowing anonymous users to enumerate available tools, retrieve sensitive enterprise data, and in some cases access destructive backend actions, credentials, or code-execution capabilities. Wiz found MCP deployments in 80% of surveyed cloud environments; roughly one in six environments had at least one publicly exposed server, 70% of those servers disclosed tool inventories anonymously, and 42% returned real data to unauthenticated tool calls.
Many affected deployments use the pre-authentication 2024-11-05 MCP protocol version rather than releases supporting OAuth 2.1 authorization, introduced in March 2025. Organizations should inventory internet-facing MCP endpoints, restrict public exposure, require authorization before tool execution, apply least-privilege permissions to connected backend credentials, and retain agent prompt and tool-invocation logs for detection and investigation.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
A March 2025 revision to the Model Context Protocol specification added authentication support based on OAuth 2.1. The revision also introduced tool annotations, including readOnlyHint and destructiveHint, to distinguish read operations from potentially dangerous writes.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.