CVE-2026-9680
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-1188
- Published
- 2026-07-28
- Last modified
- 2026-07-28
Affected products
- Alibaba Alibaba Cloud RDS OpenAPI MCP Server
Weakness type
Related vulnerabilities
- CVE-2026-87827 — KGUARD DVR unauthenticated remote command execution vulnerability
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
- CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs
- CVE-2026-75062 — Eval Injection in google/langfun via default lf.query protocol
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-77915 — rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
- CVE-2026-62388 — NLTK before 3.10.0 Insecure Default Configuration in pathsec.py