www.securityweek.com 6/26/2026, 8:31:02 AM · external

MCP update adds stateless layer, sparks security worries

MCP update adds stateless layer, sparks security worries
CyberSIXT Evidence Panel
Primary Source akamai.com

THE Model Concept Protocol (MCP) is transforming from a single-user AI integration tool to a robust enterprise-ready version by July 28, 2026. This change introduces a stateless protocol layer and involves six Specification Enhancement Proposals (SEPs). Although the new version eliminates several vulnerabilities like session hijacking, it also surfaces new security challenges, particularly regarding implementation quality.

Key improvements include end-to-end authentication, but risks like tracking identifier predictability and data leakage via HTTP headers have emerged. Akamai highlights that developers must now bear increased security responsibilities due to the protocol's new features, indicating a shift from protocol-enforced security to implementation-based control. Overall, enterprises need to adapt within the next 12 months to ensure secure deployment of the MCP.

View Primary Source Via www.securityweek.com

Article by CyberSIXT