CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
Bulletin ID: 2026-052-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/06/2026 13:45 PM PDT Description: Amazon mcp-gateway-registry is an open-source gateway and registry for Model Context Protocol (MCP) servers, providing centralized discovery, authentication/authorization, and proxying of MCP tools for AI agents. We identified CVE-2026-14471, an issue in the metrics-service retention policy management component where a caller-supplied table_name value is interpolated into SQL statements in identifier position without proper neutralization. An authenticated remote user is able to supply a crafted table_name value to execute arbitrary SQL queries against the metrics database. This allows the user to read stored data (including API key material) and to delete or alter stored data. Impacted versions: >=1.0.3 AND <=1.0.12 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- An authenticated SQL injection vulnerability allows a user to execute arbitrary SQL queries.
- Who is affected
- Authenticated users of the mcp-gateway-registry within the specified version range.
- Urgency
- Remediation is critical due to the potential for data manipulation and exposure of sensitive information.
- Action
- Upgrade to a version outside the affected range.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch mcp-gateway-registry
Get an email when a new mcp-gateway-registry advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-052-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-144710.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14471 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20