Oracle MCP Server Helper Tool SQL Injection Vulnerability

Vulnerability

A vulnerability exists in the Oracle MCP Server Helper Tool, specifically in versions 1.0.1 through 1.0.156. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the tool by executing malicious SQL. The issue arises in the helper tool component of the Oracle Open Source Projects.

Impact

Exploitation of this vulnerability allows for arbitrary SQL execution within the Oracle MCP Server Helper Tool.

Added: May 5, 2026, 4:22 AM
Updated: May 5, 2026, 4:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
7.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.