External risk intelligence

MySQL MCP Server Unauthenticated Database Access and File Modification

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-59971

The service defaults to binding to 0.0.0.0, which can make it reachable over a network. However, as a Model Context Protocol server, it is primarily intended for local developer or application-specific integrations rather than as a public-facing internet service. While it can be misconfigured to be internet-accessible, it is not typically deployed as a public-facing gateway or web application.

Missing Authentication

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the MySQL MCP Server, a component used for secure database interactions. The issue, present in versions prior to 0.4.2, could allow unauthenticated network attackers to access, modify, or even execute code via the database. While the default transport method is unaffected, misconfigurations enabling network access could lead to significant data compromise and potential system control.

  • Unsecured database access allows data theft or changes.
  • Critical flaw impacts secure database interaction components.
  • Confirm relevance and exposure to sensitive data.

Attack Path

How an attacker could exploit the issue

A network attacker can reach the MySQL MCP Server without authentication, either directly or by tricking a user's browser into sending requests through DNS rebinding. This allows the attacker to execute arbitrary SQL queries through the `cursor.execute()` function. If the database account has file privileges, the attacker could potentially read or write server files, leading to code execution.

  • No authentication required.
  • Execute arbitrary SQL queries.
  • Disclosure, modification, and code execution.

Live Threat

Current exploitation, exposure, and threat context

A network attacker could exploit this vulnerability to directly execute SQL queries, potentially leading to unauthorized access and modification of the configured database. If the MySQL account has FILE privileges, this could extend to reading or writing server files, and possibly enable code execution.

  • Database and server files at risk.
  • Unauthenticated network access to execute SQL.
  • Unauthorized data access, modification, or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The MySQL MCP Server, when configured with `MCP_TRANSPORT=sse`, is susceptible to unauthenticated database disclosure and modification, with potential for file system access and code execution if the MySQL account has FILE privileges. Ownership likely falls to application or platform teams responsible for the MySQL MCP Server instances, with initial triage focusing on identifying all deployments, assessing their network exposure and criticality, and confirming the accountable owner for remediation planning.

  • Application or platform teams own the issue.
  • Verify network exposure and criticality first.
  • Plan remediation based on verified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the MySQL MCP Server?

The MySQL MCP Server is a component designed to facilitate communication between AI agents and MySQL databases using the Model Context Protocol. It acts as an intermediary, allowing applications to interact with database records securely. It is frequently utilized in local development environments or integrated into specific application workflows where automated database access is required for query execution and data retrieval.

What does this CVE mean for database security?

This vulnerability stems from missing authentication (CWE-306) and a lack of DNS rebinding protection (CWE-346). Because the server fails to verify requests, an unauthorized party can send commands directly to the database. If the connected database account has high-level permissions, such as the ability to read or write local files, an attacker could potentially gain unauthorized control over the server hosting the database.

How is this vulnerability triggered?

The flaw is triggered specifically when the server is configured to use the SSE (Server-Sent Events) transport method. If you use the default stdio transport instead, your deployment is not affected by this issue. When SSE is active, the lack of security settings in the server code creates an open path for unauthenticated network requests or browser-based attacks via DNS rebinding.

Is my instance at risk?

Halo Surface Signal notes that while the service defaults to binding to all network interfaces, it is primarily meant for local use, not as a public-facing web service. You are most at risk if your instance is misconfigured to be internet-accessible. However, even internal instances are vulnerable if an attacker can trick a user's browser into interacting with the service from within your private network.

What should I do to secure my environment?

The first priority is to update the MySQL MCP Server to version 0.4.2 or later, which contains the fix. While preparing the update, assess your current deployments to determine if they are exposed to the network. If your team uses this component, verify the permissions of the MySQL account connected to the server and ensure it follows the principle of least privilege to limit potential impact.

References