Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL.
References
Configurations
No configuration.
History
05 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 |
05 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 04:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35228
Mitre link : CVE-2026-35228
CVE.ORG link : CVE-2026-35228
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
