CVE-2026-85787
Last modified
CVE-2026-85787 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. To remediate this issue, users should upgrade to version 1.1.7 or above..
Description
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server. To remediate this issue, users should upgrade to version 1.1.7 or above.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Amazon | postgres-mcp-server | < 1.1.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85787?
How severe is CVE-2026-85787?
How do I fix CVE-2026-85787?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8576Inappropriate implementation in CORS in Google Chrome on Lin…4.3
- CVE-2026-85769A flaw was found in libtpms, a library that provides softwar…6.5
- CVE-2026-8577Integer overflow in Fonts in Google Chrome prior to 148.0.77…8.8
- CVE-2026-8578Out of bounds read in GPU in Google Chrome on Linux prior to…3.1
- CVE-2026-85781Unverified ownership of a storage access point in the volume…8.7
- CVE-2026-85786Improper handling of highly compressed data in Amazon ion-ja…7.5
- CVE-2026-8579Insufficient validation of untrusted input in Skia in Google…3.1
- CVE-2026-8580Use after free in Mojo in Google Chrome prior to 148.0.7778.…9.6
- CVE-2026-8581Use after free in GPU in Google Chrome prior to 148.0.7778.1…8.8
- CVE-2026-8582Object lifecycle issue in Dawn in Google Chrome prior to 148…5.3
- CVE-2026-8583Insufficient policy enforcement in WebXR in Google Chrome on…5.3
- CVE-2026-8584Inappropriate implementation in Views in Google Chrome on iO…4.2
Are you affected by CVE-2026-85787?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
