CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-14471

highCVSS 8.1covered by 2 sourcesfirst seen 2026-07-06
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later.

CSIRTS triage

What
An authenticated SQL injection vulnerability allows a user to execute arbitrary SQL queries.
Who is affected
Authenticated users of the mcp-gateway-registry within the specified version range.
Urgency
Remediation is critical due to the potential for data manipulation and exposure of sensitive information.
Action
Upgrade to a version outside the affected range.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-14471

Get an email if CVE-2026-14471 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-14471

CVE.org record

Embed the live status

CVE-2026-14471 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-14471 status](https://www.csirts.com/badge/CVE-2026-14471)](https://www.csirts.com/cve/CVE-2026-14471)