OS Command Injection Vulnerability in Amazon's PostgreSQL MCP Server
CVE-2026-87911

9CRITICAL

Key Information:

Vendor

Aws

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87911?

A security vulnerability exists in the read-only enforcement of the SQL validation component in Amazon's PostgreSQL MCP Server prior to version 1.1.7. This flaw allows an unauthenticated user to exploit a crafted COPY ... TO PROGRAM statement, potentially enabling unauthorized execution of operating system commands on the host of a self-managed PostgreSQL server when authenticated users interact with the MCP server. Upgrading to version 1.1.7 or later is strongly advised to mitigate this risk.

Affected Version(s)

AWS Labs postgres MCP Server 0 < 1.1.7

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Corsen AI
.