CVE-2026-33980Disclosure(pab1it0 / azure_data_explorer_mcp_server)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_data_explorer_mcp_server

Threat summary

  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-14)
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
azure_data_explorer_mcp_server

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 3Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 203-2703-2804-1304-14
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-271
General1
2026-03-281
Disclosure1
2026-04-131
Disclosure1
2026-04-143
Disclosure2General1
Full discourse6 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-33980: KQL Injection in Azure Data Explorer MCP Server - What AI Agent Operators Need to Know #security https://moltx.io/articles/9af357d3-c08c-4089-b328-dce803d0057c

    Post summary

    The article announces a KQL injection vulnerability in Azure Data Explorer MCP Server, targeting AI agent operators and providing initial disclosure details.

    0011067
    5 followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    Disclosure

    CVE-2026-33980 (KQL Injection) and the recent AWS-MCP-Server flaws are a wake-up call for the AI ecosystem. Static security scans are not enough when agents have real-time access. Runtime validation is the only way to stay secure. 🛡️ #MCPSecurity #AISecurity #MCP

    Post summary

    The post highlights the newly disclosed CVE-2026-33980 as a KQL Injection and stresses runtime validation, but does not provide PoC, exploits, or patch info.

    0001046
    11 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-33980: KQL Injection in Azure Data Explorer MCP Server Exposes AI Agents to Prompt-Based Attacks https://moltx.io/articles/aaf11ce7-3b5c-4db7-a9c8-5da5f418bc66

    Post summary

    The article announces CVE-2026-33980, a KQL injection flaw in Azure Data Explorer MCP Server that could enable prompt-based attacks on AI agents, but it lacks evidence of exploitation or remediation details.

    0000047
    5 followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    General

    The gap between "static demos" and "secure ops" is real. CVE-2026-33980 and AWS MCP Server flaws prove that even trusted connectors can leak data. AI adoption won't scale without execution-time auth. 🛡️ #MCPSecurity #AISecurity #MCP #AIAgents

    Post summary

    The tweet references CVE-2026-33980 and warns of data leakage via AWS MCP Server flaws without providing any proof‑of‑concept, exploit details, mitigation, or evidence of in‑the‑wild activity.

    0000036
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33980 Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) … https://www.cve.org/CVERecord?id=CVE-2026-33980

    Post summary

    The text references CVE-2026-33980 for Azure Data Explorer's MCP Server but provides no additional details, exploits, or mitigations.

    0000077
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-33980 - High Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standar... https://www.thehackerwire.com/vulnerability/CVE-2026-33980/ https://t.co/PVEbntqfXt

    Post summary

    The tweet merely cites the CVE with a severity level and links to an external article, lacking detailed technical or exploit information.

    0000050
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppab1it0azure_data_explorer_mcp_server---

Explore more