CVE-2026-87911: Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server

Published Sep 9, 2026
·
Updated

An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode.

To remediate this issue, users should upgrade to version 1.1.7 or later.

Affected Software

1 affected component
Amazon awslabs postgres-mcp-server<1.1.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Amazon awslabs postgres-mcp-server to a version that resolves this vulnerability.

    Fixed in 1.1.7

Event History

Sep 9, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Self-managed PostgreSQL server hosts running Amazon awslabs postgres-mcp-server before version 1.1.7 are exposed when the MCP server processes attacker-controlled content during an authenticated user's interaction. The affected mode is the default read-only mode.

2

Does an attacker need credentials or direct database access?

The actor is described as unauthenticated, but exploitation requires them to place a crafted COPY ... TO PROGRAM statement into content that is later processed when an authenticated user interacts with the MCP server. No direct database access requirement is stated.

3

What can happen if exploitation succeeds?

An attacker may execute operating system commands on the host running the self-managed PostgreSQL server. The reported impact includes high confidentiality, integrity, and availability effects.

4

What should teams do if they are affected?

Upgrade Amazon awslabs postgres-mcp-server to version 1.1.7 or later. The provided data does not specify an alternative mitigation for environments that cannot immediately upgrade.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203