Security researchers report that a significant share of Model Context Protocol (MCP) access policies are broken or missing
Security issue Provisional 74% confidence first seen
A review found that more than 20% of MCP-related access policies were either broken or missing. The coverage attributes common failures to issues such as use of personal tokens without rotation schedules and insufficient audit logging as MCP authorization features have evolved.