CVE-2026-9680

Summary

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Affected Software

VendorProductVersion RangeStatus
AlibabaAlibaba Cloud RDS OpenAPI MCP Server1.8.0 <= 3.1.2affected

Weaknesses

  • CWE-1188: CWE-1188 Initialization of a resource with an insecure default

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References