Security Advisory

CVE-2026-9680

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-28 09:05:30
Last updated 2026-07-28 16:08:06
Assigner alibaba
CVSS score not scored
State PUBLISHED

Description

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.