CVE-2026-35228General

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-05); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-08: 1Mentions · 2026-05-30: 1Mentions · 2026-06-10: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-10: 105-0505-0805-3006-10
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure1General1
2026-05-081
General1
2026-05-301
Disclosure1
2026-06-101
General1
Full discourse5 posts
  • teambi0s@teambi0s
    Disclosure

    Proud to share that our Web Team Lead, @k0w4lzk1, has been credited with two CVEs: • CVE-2026-35228: SQL Injection in Oracle's MCP Server Helper Tool • CVE-2026-41591: XSS in eBay's Marko framework Congrats to Kartik on the disclosures!

    Post summary

    A brief announcement acknowledges two CVEs with basic vulnerability types (SQL Injection and XSS), but offers no PoC, exploitation details, or patch information.

    3202711.1K
    3.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35228 Unauthenticated SQL Injection in Oracle MCP Server Helper Tool 1.0.1-1.0.156 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35228

    Post summary

    The text announces an unauthenticated SQL injection vulnerability (CVE-2026-35228) affecting Oracle MCP Server Helper Tool versions 1.0.1 through 1.0.156, without any mention of exploits, patches, or active attacks.

    0101050
    4.0K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVE-2026-35228 is a good patch-discipline check. Affected systems / remote code execution. Public details are enough to start scoping. Who owns the affected surface?

    Post summary

    The message acknowledges CVE‑2026‑35228 as a remote code execution vulnerability but lacks concrete details on PoC, exploitation, or patch availability.

    1000040
    315 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Oracle ❗ CVE-2026-35228 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-oracle-6/ https://t.co/Swqa0uAlO4

    Post summary

    The tweet announces a CVE (CVE-2026-35228) affecting Oracle products and directs readers to a link for more information, but lacks further technical or exploit details.

    00000115
    6.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-35228 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Oracle Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-35228 #CVE-2026-35228 #CVE #High #Oracle #CyberSecurity #InfoSec https://t.co/0PtfEQBGT4

    Post summary

    The tweet announces CVE-2026-35228 with severity and vendor but offers no deeper details or actionable information.

    0000046
    151 followersView on X

Explore more