CVE-2026-73554 is a critical authentication bypass vulnerability in Dolt MCP affecting versions 0.3.1 through 0.3.6 when deployed with remote HTTP transport and JWT authentication enabled. The flaw arises from two conditions in the request handling chain: JWT rejection logic writes an HTTP 401 response for an invalid token but does not terminate execution because the middleware omits a return statement, and session validation in the underlying mcp-go implementation accepts forged session identifiers matching an expected format without verifying that the session was actually created by the server. By combining an invalid JWT with a crafted session identifier, an unauthenticated attacker can bypass intended access controls, reach the MCP tool dispatcher, and invoke database operations through the server context despite failed authentication. A notable characteristic is that the server may still return HTTP 401 Unauthorized while including the result of the unauthorized operation in the response body.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.