CVE-2026-35228: SQL Injection
Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35228?
The severity of CVE-2026-35228 is considered high due to its exploitability by unauthenticated attackers over HTTP.
How do I fix CVE-2026-35228?
To fix CVE-2026-35228, users should upgrade to a patched version of the Oracle MCP Server Helper Tool beyond 1.0.156.
Who is affected by CVE-2026-35228?
Any users running the affected versions of the Oracle MCP Server Helper Tool from 1.0.1 to 1.0.156 are at risk.
What type of vulnerability is CVE-2026-35228?
CVE-2026-35228 is classified as an unauthenticated remote code execution vulnerability.
Can CVE-2026-35228 be exploited remotely?
Yes, CVE-2026-35228 can be exploited remotely by an unauthenticated attacker with network access.