OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-61742

CRITICAL · CVSS 9.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

DBHub versions prior to 0.22.5 are vulnerable due to an unauthenticated HTTP MCP endpoint that can be exploited via DNS rebinding, allowing attackers to execute MCP tool calls directly from a victim's browser. This could lead to unauthorized access to sensitive database information, including reading and writing capabilities depending on the database configuration and permissions. Organizations using affected versions of DBHub should prioritize this vulnerability to mitigate potential data breaches and unauthorized database manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61742
Severity
CRITICAL
CVSS
9.3
EPSS
0.20%
Oracle

Original NVD Description

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The HTTP server attempts to protect browser-origin access by checking whether the `Origin` hostname equals the `Host` hostname, then reflecting the validated `Origin` into `Access-Control-Allow-Origin`. This does not stop DNS rebinding. After an attacker-controlled hostname rebinds to a victim-accessible DBHub HTTP server, both `Origin` and `Host` can contain the attacker-controlled hostname, so DBHub accepts the request and dispatches MCP tool calls. As a result, a malicious website can deterministically invoke DBHub MCP tools from the victim's browser without prompt injection or model involvement. With the default demo configuration this can read and write the demo SQLite database; with a real configured database, the same primitive can read, enumerate, and potentially write database contents depending on DBHub's configured tool permissions and database credentials. Version 0.22.5 fixes the issue.