CVE-2026-9680

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-28 09:16

Updated : 2026-07-28 20:35


NVD link : CVE-2026-9680

Mitre link : CVE-2026-9680

CVE.ORG link : CVE-2026-9680


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Initialization of a Resource with an Insecure Default