Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2025-66336: SQL injection and authorization bypass in Apache Doris MCP Server

Apache Doris MCP Server contains a SQL injection flaw where a user-controlled database name is interpolated into a metadata query that is executed without the caller's authorization context, letting an authenticated (or anonymous, if auth is disabled) attacker bypass SQL security validation and read metadata outside the intended database scope. The issue is fixed in version 0.6.1.

Disclosed 22 June 2026 · Record updated 13 September 2026

Impact

Attackers could bypass SQL security validation and access database metadata beyond the intended scope.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-66336