SQL Injection Vulnerability in Oracle MCP Server Helper Tool
CVE-2026-35228
8.7HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 5 May 2026
What is CVE-2026-35228?
The Oracle MCP Server Helper Tool contains a vulnerability that allows unauthenticated attackers with network access via HTTP to exploit the system. Successful exploitation enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized data manipulation or loss. This vulnerability affects specific supported versions and requires immediate attention to safeguard against exploitation. It is crucial for users to apply the recommended security patches to maintain the integrity and security of their systems.
Affected Version(s)
Oracle MCP Server Helper Tool product of Oracle Open Source Projects 1.0.1-1.0.156