VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-35228

CVE-2026-35228: Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The

Published May 5, 2026 CVSS 8.7

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL.

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.