{"id":"CVE-2026-103068","title":"Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.","summary":"Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-266"],"vendor":"ByteCore Stack","product":"bcs-mcp-manager","affected":["bcs-mcp-manager >= n/a <= 1.2.2"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:31:55.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103068","references":[{"url":"https://patchstack.com/database/wordpress/plugin/bcs-mcp-manager/vulnerability/wordpress-bytecorestack-mcp-connector-for-ai-tools-plugin-1-2-2-privilege-escalation-vulnerability?_s_id=cve","label":"audit@patchstack.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-01T16:19:50.356732Z"},"ingestedAt":"2026-10-01T14:46:26.710Z","slug":"CVE-2026-103068","body":"## Overview\n\nSubscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}