Unauthenticated HTTP Endpoints Exposing Database MCP Server - DBHub by Bytebase
CVE-2026-61742

9.3CRITICAL

Key Information:

Vendor

Bytebase

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-61742?

DBHub, a database MCP server supporting multiple database types like Postgres and MySQL, has a vulnerability stemming fromunauthenticated HTTP MCP endpoints available in versions prior to 0.22.5. This issue arises when running the server in HTTP transport mode, potentially allowing attackers to exploit DNS rebinding vulnerabilities. If an attacker successfully rebinds a hostname to the DBHub HTTP server, they can manipulate the Origin and Host headers to invoke malicious MCP tool calls from the victim's browser. This exploitation could enable unauthorized access to read, enumerate, and write database contents, depending on the configurations and permissions set on DBHub. The issue was addressed in version 0.22.5.

Affected Version(s)

dbhub < 0.22.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.