SQL Injection Vulnerability in Oracle MCP Server Helper Tool
CVE-2026-35228

8.7HIGH

What is CVE-2026-35228?

The Oracle MCP Server Helper Tool contains a vulnerability that allows unauthenticated attackers with network access via HTTP to exploit the system. Successful exploitation enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized data manipulation or loss. This vulnerability affects specific supported versions and requires immediate attention to safeguard against exploitation. It is crucial for users to apply the recommended security patches to maintain the integrity and security of their systems.

Affected Version(s)

Oracle MCP Server Helper Tool product of Oracle Open Source Projects 1.0.1-1.0.156

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.