CVE-2026-9680 MEDIUM

CVE-2026-9680: MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server

Vendor Alibaba
Product Alibaba Cloud RDS OpenAPI MCP Server
Weakness CWE-1188
Published July 28, 2026
Last update July 28, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Key dates

02Disclosure timeline

July 28, 2026 CVE published