OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-61788

HIGH · CVSS 7.4 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

DBHub, a database MCP server for various database systems, contains a vulnerability that allows unauthorized write operations despite a `readonly = true` setting due to misconfigured connection handling. This flaw can lead to severe consequences, including sequence tampering, arbitrary file writing, and remote code execution, especially when exploited by users with privileged roles. Organizations using affected versions of DBHub should prioritize upgrading to version 0.22.6 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61788
Severity
HIGH
CVSS
7.4
EPSS
0.30%
Oracle

Original NVD Description

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_transaction_read_only=on` (and open SQLite in `readOnly` mode), but that code is gated on a config value that is never populated, so it never runs. The only thing left enforcing read-only is a classifier that inspects the first keyword of each statement. Any `SELECT` that writes or has side effects through a function call passes it. With an ordinary role this allows sequence tampering; with a privileged role it allows writing arbitrary files on the server (`lo_export`), reading arbitrary host files (`pg_read_file`), and remote code execution (`dblink` + `COPY ... TO PROGRAM`). The HTTP transport is unauthenticated and binds to `0.0.0.0` by default, so this is reachable by any network caller of `/mcp`. Version 0.22.6 patches the issue.