Improper Exposure of MCP Server in Alibaba Cloud's RDS Product
CVE-2026-9680
5.8MEDIUM
What is CVE-2026-9680?
The vulnerability arises from the improper exposure of the MCP server in Alibaba Cloud's RDS product, which permits unauthorized remote attackers to invoke critical MCP tools. This occurs due to an MCP endpoint listening on all network interfaces by default, enabling potential exploitation through network access. It is vital for users to apply security best practices and restrict access to sensitive services to mitigate such vulnerabilities.
Affected Version(s)
Alibaba Cloud RDS OpenAPI MCP Server 1.8.0 <= 3.1.2
