CVE-2026-48774: ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contract

Published Jun 19, 2026
·
Updated

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP runsqlreadonly tool violates its documented read-only contract for MySQL targets. The tool validates only the full input string with a substring blacklist and first-keyword allowlist, but then executes the entire SQL string on a backend connection created with CLIENTMULTISTATEMENTS. As a result, a caller can submit a read-only first statement followed by a side-effecting second statement, such as SELECT 1; RENAME TABLE .... The validator accepts the payload because it starts with SELECT and because side-effecting MySQL statements such as RENAME TABLE, SET, RESET, LOCK TABLES, and KILL are not rejected by the blacklist. In a live MCP runtime test, the /mcp/query endpoint accepted a runsqlreadonly request. The MCP response reported success for the first SELECT, and direct backend verification showed that the table had actually been renamed. This violates the endpoint's read-only security contract and lets an MCP caller perform backend writes or administrative SQL, limited by the configured MCP target account's database privileges. Version 3.0.9 contains a fix. Other operator mitigations include: keeping MCP disabled unless required; setting a non-empty mcp-queryendpointauth token before exposing /mcp/query; restricting MCP listener network exposure; configuring MCP backend target credentials as database-level read-only users; and adding temporary MCP query rules to block obvious multi-statement patterns.

Affected Software

1 affected component
ProxySQL ProxySQL>=3.0.0<=3.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ProxySQL to a version that resolves this vulnerability.

    Fixed in 3.0.9
  2. Configuration

    Keep MCP disabled unless required (disable MCP when not needed)

    ProxySQL MCP MCP = disabled
  3. Configuration

    Set a non-empty mcp-query_endpoint_auth token before exposing the /mcp/query endpoint

    ProxySQL MCP mcp-query_endpoint_auth = non-empty
  4. Configuration

    Configure MCP backend target credentials as database-level read-only users

    MCP backend target credentials database privileges = read-only
  5. Configuration

    Add temporary MCP query rules to block obvious multi-statement SQL patterns to prevent execution of side-effecting multi-statements

    ProxySQL MCP query rules query_rules = block multi-statement patterns (temporary)
  6. Compensating control

    Restrict MCP listener network exposure (limit access to trusted/internal IPs and networks)

Event History

Jun 19, 2026
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48774?

CVE-2026-48774 has a high severity rating of 7.5.

2

How do I fix CVE-2026-48774?

To fix CVE-2026-48774, update ProxySQL to version 3.0.9 or later.

3

What are the risks associated with CVE-2026-48774?

CVE-2026-48774 may allow unintended side-effecting MySQL multi-statements to execute despite a read-only contract.

4

Which versions of ProxySQL are affected by CVE-2026-48774?

ProxySQL versions 3.0.0 through 3.0.8 are affected by CVE-2026-48774.

5

What happens if CVE-2026-48774 is exploited?

If exploited, CVE-2026-48774 can result in unauthorized modifications to the database due to the violation of the read-only contract.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203