CVE-2026-9680: Alibaba Cloud Rds Openapi Mcp Server

Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default.

Affected products

  • Alibaba Alibaba Cloud Rds Openapi Mcp Server: from 1.8.0, up to and including 3.1.2

Published 2026-07-28. Last modified 2026-07-28.