CVE-2026-59726
Summary
Maximum-severity flaw in the Ruflo Model Context Protocol bridge — publicly nicknamed "RufRoot" — which exposed 233 privileged tools, including shell execution and database management, over an unauthenticated interface bound to the network by default.
Details
This is the AI-tooling equivalent of leaving an RDP port open: the MCP bridge is the component that gives an assistant its tools, and the tool list in question includes command execution and database access, so unauthenticated reachability is straight to remote code execution without any prompt-injection step. The digest recorded it for its effect on Claude Code and Codex workflows rather than as an isolated product bug — the clients are only as constrained as the bridge they are pointed at. The corrective action is network placement and authentication on the bridge, which are deployment decisions a patch can enforce but not decide; the flaw's nickname is not a vendor identifier and should not be cited as one.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-59726 |
| CVSS | 10.0 |
| Vendor / product | Ruflo (MCP bridge) |
| Reported in the digest | 2026-07-30 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-30.md