This tracks exactly with why I built MCP Gateway — the root causes you listed (absent authentication, blind trust, no access control) are all things the protocol leaves up to each implementer to solve independently. https://github.com/PanosSalt/MCP-Gateway OAuth 2.1 + PKCE, Microsoft Entra SSO, per-tool RBAC, full audit trail on every tool call. The gateway sits in front of your tools so auth and access control are s…
Re: MCP Security 2026: 30 CVEs in 60 Days
#11[dead]