Improper Exposure of MCP Server in Alibaba Cloud's RDS Product
CVE-2026-9680

5.8MEDIUM

Key Information:

Vendor

Alibaba

Vendor
CVE Published:
28 July 2026

What is CVE-2026-9680?

The vulnerability arises from the improper exposure of the MCP server in Alibaba Cloud's RDS product, which permits unauthorized remote attackers to invoke critical MCP tools. This occurs due to an MCP endpoint listening on all network interfaces by default, enabling potential exploitation through network access. It is vital for users to apply security best practices and restrict access to sensitive services to mitigate such vulnerabilities.

Affected Version(s)

Alibaba Cloud RDS OpenAPI MCP Server 1.8.0 <= 3.1.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.