CVE-2026-71424 | onyx-dot-app Onyx up to 3.1.9/3.2.13/3.x MCP API api.py OnyxTokenStorage.set_tokens improper authorization

SecurityVulns

A vulnerability was found in onyx-dot-app Onyx up to 3.1.9/3.2.13/3.x. It has been declared as problematic. This impacts the function OnyxTokenStorage.set_tokens of the file backend/onyx/server/features/mcp/api.py of the component MCP API. The manipulation results in improper authorization.

This vulnerability was named CVE-2026-71424. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More