CVE-2026-85787CWE-184

CVE-2026-85787

Medium · published September 5, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
9.3
In the wild
Unconfirmed
What it is

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.

To remediate this issue, users should upgrade to version 1.1.7 or above.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v4.0
7.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00196 · 9.3th percentile
Weakness
CWE-184 · Incomplete List of Disallowed Inputs
Published
2026-09-05T01:17Z
References (2)
EPSS history
Timeline
  • 06 SEP 03:33Z
    EPSS moved — → 0%
    epss
  • 04 SEP 20:03Z
    An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server
    cvelistv5