What is CVE-2026-48039?
CVE-2026-48039 is an authentication bypass vulnerability in Meta Ads MCP server, which allows AI assistants to run Meta Ads. Prior to version 1.0.109, the `AuthInjectionMiddleware.dispatch()` function unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers. Users should immediately upgrade to version 1.0.109 or later.
Azərbaycanca: CVE-2026-48039, AI köməkçilərinin Meta Ads işlətməsinə imkan verən Meta Ads MCP serverində autentifikasiyadan yan keçmə zəifliyidir. 1.0.109 versiyasından əvvəlki versiyalarda `AuthInjectionMiddleware.dispatch()` funksiyası autentifikasiya olunmamış Streamable HTTP sorğularını birbaşa MCP alət işləyicilərinə ötürür. İstifadəçilər dərhal 1.0.109 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What product is affected by CVE-2026-48039 and what is its root cause?
CVE-2026-48039 is an authentication bypass vulnerability found in the Meta Ads MCP server, which allows AI assistants to run Meta Ads. The root cause is that in versions prior to 1.0.109, the `AuthInjectionMiddleware.dispatch()` function unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers.
What should users do to mitigate CVE-2026-48039?
Users should immediately upgrade the Meta Ads MCP server to version 1.0.109 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.