Skip to main content
Vulnerability Database/CVE-2026-86122

CVE-2026-86122: Rowboat SSRF Vulnerability

CVE-2026-86122 is a server-side request forgery flaw in Rowboat through version 0.9.1 that allows authenticated users to target internal services and cloud metadata endpoints. This post covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-86122 Overview

CVE-2026-86122 is a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] affecting Rowboat through version 0.9.1. The application fails to validate custom Model Context Protocol (MCP) server URLs and webhook URLs supplied by authenticated users. Attackers with valid credentials can configure these destinations to point at internal services and cloud provider metadata endpoints. This allows enumeration of internal network topology and unauthorized access to internal HTTP resources.

Critical Impact

Authenticated attackers can coerce the Rowboat server into issuing HTTP requests to arbitrary internal destinations, including cloud metadata endpoints, enabling internal reconnaissance and potential credential exposure.

Affected Products

  • Rowboat through version 0.9.1
  • Rowboat custom MCP server integration (add-custom-mcp-server.use-case.ts)
  • Rowboat agent tools runtime (agent-tools.ts)

Discovery Timeline

  • 2026-09-05 - CVE-2026-86122 published to NVD
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-86122

Vulnerability Analysis

Rowboat accepts user-supplied URLs for two integration surfaces: custom MCP servers and webhooks. Neither input path performs destination validation before the server issues an outbound HTTP request. Authenticated users can therefore direct the application to fetch arbitrary internal resources.

The attack surface is significant in cloud deployments. Cloud provider metadata endpoints such as 169.254.169.254 frequently expose instance credentials, IAM role tokens, and configuration data. Internal admin panels and unauthenticated service ports become reachable from the trusted network position of the Rowboat application.

The issue is tracked in Rowboat Issue #621 and documented in the VulnCheck Rowboat SSRF Advisory.

Root Cause

The root cause is missing URL validation in the custom MCP server registration flow and webhook configuration flow. The relevant logic in add-custom-mcp-server.use-case.ts and agent-tools.ts accepts arbitrary URL schemes and hostnames without denylisting private IP ranges, link-local addresses, or loopback destinations.

Attack Vector

Exploitation requires an authenticated Rowboat account with permission to add a custom MCP server or configure a webhook. The attacker submits a URL pointing to an internal target, such as http://169.254.169.254/latest/meta-data/ on AWS or http://metadata.google.internal/ on GCP. When Rowboat processes the integration, it issues the outbound request from within the application's trust boundary and may return response data to the attacker. See the VulnCheck Rowboat SSRF Advisory for further technical detail.

Detection Methods for CVE-2026-86122

Indicators of Compromise

  • Outbound HTTP requests from the Rowboat host to RFC 1918 private address ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  • Requests originating from Rowboat to cloud metadata endpoints such as 169.254.169.254 or metadata.google.internal.
  • Custom MCP server or webhook configuration entries containing loopback (127.0.0.1, localhost) or link-local hostnames.
  • Unusual spikes in webhook or MCP registration activity from a single authenticated account.

Detection Strategies

  • Inspect Rowboat application logs for MCP server and webhook add events and correlate the target URL against a denylist of internal ranges.
  • Deploy egress network monitoring that flags any application-originated traffic to metadata service IP addresses.
  • Audit stored MCP and webhook configurations for URLs that resolve to internal or reserved addresses.

Monitoring Recommendations

  • Enable outbound proxy logging for the Rowboat workload and alert on non-approved destination hosts.
  • Monitor cloud audit logs for unexpected use of instance metadata service credentials outside their normal calling context.
  • Track authenticated user actions that create or modify integration endpoints, and review them during regular access recertification.

How to Mitigate CVE-2026-86122

Immediate Actions Required

  • Restrict Rowboat's outbound network egress to an explicit allowlist of required external hostnames.
  • Enforce Instance Metadata Service Version 2 (IMDSv2) on AWS deployments to require session-token-based metadata access.
  • Review all existing custom MCP server and webhook configurations and remove entries pointing to internal or reserved address ranges.
  • Limit which authenticated roles can register custom MCP servers or configure webhook destinations.

Patch Information

At the time of publication, the enriched CVE data does not list a fixed version. Rowboat is affected through version 0.9.1. Monitor the Rowboat GitHub repository and Rowboat Issue #621 for a patched release and apply it as soon as it becomes available.

Workarounds

  • Place Rowboat behind an egress proxy that denies requests to RFC 1918 ranges, loopback, and link-local addresses including 169.254.169.254.
  • Apply network policies or security groups that block the Rowboat workload from reaching cloud metadata endpoints unless required.
  • Disable the custom MCP server and webhook features until a validated fix is deployed if these capabilities are not in active use.
  • Require administrator approval workflows for new MCP or webhook destinations to prevent silent abuse by lower-privileged accounts.
bash
# Example: block metadata endpoint access from the Rowboat container
iptables -A OUTPUT -d 169.254.169.254 -j DROP
iptables -A OUTPUT -d 127.0.0.0/8 ! -o lo -j DROP
iptables -A OUTPUT -d 10.0.0.0/8 -j DROP
iptables -A OUTPUT -d 172.16.0.0/12 -j DROP
iptables -A OUTPUT -d 192.168.0.0/16 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.