CVE-2026-35228: Oracle MCP Server Helper Tool flaw allows malicious SQL execution
Oracle disclosed an easily exploitable vulnerability in the Oracle MCP Server Helper Tool (versions 1.0.1-1.0.156) that lets an unauthenticated attacker with HTTP network access compromise the tool and cause it to execute malicious SQL.
Disclosed 5 May 2026 · Record updated 13 September 2026
Impact
An unauthenticated remote attacker can compromise the MCP Server Helper Tool and make it execute malicious SQL, affecting versions 1.0.1 through 1.0.156.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-35228
