CVE-2026-9680

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Scoring

Severity
MEDIUM
CVSS base score
5.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS probability
0.24%
CWE
CWE-1188
Published
2026-07-28
Last modified
2026-07-28

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs