CVE-2026-14471: Aws Mcp Gateway & Registry
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later.
Affected products
- Aws Mcp Gateway & Registry: from 1.0.3, up to and including 1.0.12
Published 2026-07-06. Last modified 2026-07-07.