Vulnerabilities

MCP Specification Upgrade

June 28, 2026 08:04 · 12 min read
MCP Specification Upgrade

Introduction of MCP 2026-07-28 Specification

The Model Concept Protocol (MCP) is evolving from a single-user server to an enterprise-ready server, allowing for expanded cloud-native AI usage. The new specification, MCP 2026-07-28, will be published on July 28, 2026, with a 12-month deprecation window for legacy versions.

Key Changes and Security Implications

The new MCP introduces a platform able to support enterprise-scale, cloud-native deployments. The headline change is that MCP is now stateless at the protocol layer, with six Specification Enhancement Proposals (SEPs) working together to achieve this. However, this change also introduces subtle security challenges, as AI interactions often require a back-and-forth chain of events.

Akamai, one of the firms that has studied the new format, reports that while the protocol removes several classes of vulnerabilities, it also introduces new areas where security depends heavily on implementation quality. Improvements include an end to session hijacking, prevention of unsolicited server-initiated prompts, and stronger authentication standards.

New Attack Surfaces and Concerns

The introduction of tracking identifiers and state objects handed to the client by the server raises concerns over potentially predictable IDs, which could lead to hijacking an active workflow, accessing data belonging to a different agent, or triggering unauthorized cross-tenant actions.

Additionally, the new specification introduces MCP-specific HTTP headers, such as MCP-Method and MCP-Name, which brings two new risks: protocol confusion (Desync) attacks and data leakage via x-mcp-header. If developers accidentally map sensitive inputs like API keys, tokens, or PII to these headers, those secrets become visible to every load balancer, proxy, and logging system along the path.

Other changes that have potential attack surface concerns include the introduction of long-running tasks, which creates a massive denial-of-service (DoS) vector, and the introduction of MCP Apps as a first-class protocol extension, which improves the user experience but also introduces traditional web browser risks, such as stored cross-site scripting (XSS).

Security Responsibilities and Implementation Flaws

Maxim Zavodchik, senior director of threat research at Akamai, notes that the new enterprise-level MCP affects security teams, as critical security boundaries are now entirely dependent on how developers implement them. Enterprises will have greater responsibility for the security of their MCP servers, and implementation choices will dictate the overall security posture.

Specific areas that are highly prone to implementation flaws can lead to workflow hijacking and cross-tenant access, privilege escalation and secrets leakage, header/body inconsistencies that bypass security controls, hit-and-run DoS attacks against long-running tasks, and malicious script execution and phishing through insecure UI panels.

Akamai summarizes that the changes are not simply incremental improvements but fundamentally reshape where security responsibilities reside. Security decisions that were previously enforced by the protocol are increasingly delegated to MCP server developers and platform operators.

Conclusion and Recommendations

The advantage of having an enterprise rather than single-user MCP cannot be denied, but there is much for in-house developers and security teams to learn, understand, and implement over the next 12 months to make it secure. Companies have 12 months to get ready for the new specification, and it is essential to prioritize security and implementation quality to mitigate the potential attack surfaces and concerns introduced by the new MCP 2026-07-28 specification.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free