{"resultsPerPage":3,"startIndex":0,"totalResults":3,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-04T22:55:05.657","vulnerabilities":[{"cve":{"id":"CVE-2026-26118","sourceIdentifier":"secure@microsoft.com","published":"2026-03-10T18:18:41.180","lastModified":"2026-06-17T10:25:45.377","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network."},{"lang":"es","value":"Falsificación de petición del lado del servidor (SSRF) en Azure MCP Server permite a un atacante autorizado elevar privilegios a través de una red."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Azure MCP Server Tools 1.0.0 (npm)","versions":[{"version":"1.0.0","lessThan":"1.0.2","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Azure MCP Server Tools 1.0.0 (NuGet)","versions":[{"version":"1.0.0","lessThan":"1.0.2","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Azure MCP Server Tools 2.0.0 (npm)","versions":[{"version":"2.0.0-beta.1","lessThan":"2.0.0-beta.17","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Azure MCP Server Tools 2.0.0 (NuGet)","versions":[{"version":"2.0.0-beta.1","lessThan":"2.0.0-beta.17","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Azure MCP Server Tools 2.0.0 (PyPi)","versions":[{"version":"2.0.0-beta.1","lessThan":"2.0.0-beta.17","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-05T00:00:00+00:00","id":"CVE-2026-26118","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0.0","matchCriteriaId":"08F2F33D-68BC-40BD-9945-9DAC13516B3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta1:*:*:*:*:*:*","matchCriteriaId":"FE4BB62F-D65C-4BD7-A977-560951121A31"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta10:*:*:*:*:*:*","matchCriteriaId":"E25804B6-4EBC-484C-AA53-5F36A125F63C"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta11:*:*:*:*:*:*","matchCriteriaId":"60995316-44CA-4789-B168-BD759D3FDC7E"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta12:*:*:*:*:*:*","matchCriteriaId":"69049E0E-CFEE-4051-BE1A-E6A10A346986"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta13:*:*:*:*:*:*","matchCriteriaId":"0E72117C-2C98-424A-BF6E-78553201F3AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta14:*:*:*:*:*:*","matchCriteriaId":"AE81B2AA-87D7-41B3-934E-F06EB9973B7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta15:*:*:*:*:*:*","matchCriteriaId":"A733A0B0-6D86-4CEF-A594-214195F8A40E"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta16:*:*:*:*:*:*","matchCriteriaId":"1A0E69CE-C717-407D-84BA-8CC241F179B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta2:*:*:*:*:*:*","matchCriteriaId":"C7D01823-C2A0-4FB2-B0A9-53CD02FFDFFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta3:*:*:*:*:*:*","matchCriteriaId":"F27295F4-18D0-428E-A2F1-77B3209B6183"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta4:*:*:*:*:*:*","matchCriteriaId":"B88758F0-AE0F-4644-A2D0-EAB69F04B2AA"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta5:*:*:*:*:*:*","matchCriteriaId":"D1C2790F-D5F5-495A-9A70-01D0A69FECDF"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta6:*:*:*:*:*:*","matchCriteriaId":"F30CE925-8322-43B4-B634-B08F0D69DF19"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta7:*:*:*:*:*:*","matchCriteriaId":"640182FA-C461-46A2-BDEE-0785DCA7C26B"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta8:*:*:*:*:*:*","matchCriteriaId":"F7F3A643-AC07-4EC7-A4E2-DD5B0937D728"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta9:*:*:*:*:*:*","matchCriteriaId":"B304FD54-1827-4401-8DA9-C1D982667DBB"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33980","sourceIdentifier":"security-advisories@github.com","published":"2026-03-27T22:16:22.607","lastModified":"2026-06-17T10:38:22.570","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pab1it0","product":"adx-mcp-server","versions":[{"version":"<= 1.1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-27T21:55:57.812415Z","id":"CVE-2026-33980","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-943"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pab1it0:azure_data_explorer_mcp_server:*:*:*:*:*:*:*:*","versionEndIncluding":"0.1.0","matchCriteriaId":"B3933040-DE34-4038-ACFC-1DD6D5BA0842"}]}]}],"references":[{"url":"https://github.com/pab1it0/adx-mcp-server/commit/0abe0ee55279e111281076393e5e966335fffd30","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/pab1it0/adx-mcp-server/security/advisories/GHSA-vphc-468g-8rfp","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/pab1it0/adx-mcp-server/security/advisories/GHSA-vphc-468g-8rfp","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32211","sourceIdentifier":"secure@microsoft.com","published":"2026-04-03T00:16:04.703","lastModified":"2026-07-24T21:10:00.143","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"secure@microsoft.com","tags":["exclusively-hosted-service"]}],"descriptions":[{"lang":"en","value":"Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network."},{"lang":"es","value":"Falta de autenticación para función crítica en el servidor Azure MCP permite a un atacante no autorizado divulgar información a través de una red."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Azure Web Apps","versions":[{"version":"-","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-03T00:00:00+00:00","id":"CVE-2026-32211","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_web_apps:-:*:*:*:*:*:*:*","matchCriteriaId":"4F7255ED-CCC0-4FF2-B197-C55C4B80EEFD"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32211","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}}]}