CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope

Bulletin ID: 2026-101-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 13:00 PM PDT
Last Updated Date: 09/08/2026 09:45 AM PDT

We have identified CVE-2026-85787, an incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.

Impacted versions: any pypi package version < 1.1.7

This issue has been addressed in version 1.1.7. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Run the MCP server as a minimal-privilege Postgres role

The strongest control is to connect the MCP server using a dedicated Postgres role that has only the privileges it actually needs, so that the database itself enforces the boundary regardless of what SQL reaches it. In particular:

  • Do not connect as a superuser, rds_superuser, or the cluster master user. Those roles bypass row-level security, can read credential catalogs (pg_authid, pg_user_mappings), and can terminate other sessions.
  • For read-only use, grant only CONNECT + USAGE + SELECT on the schemas the agent needs, and force read-only transactions at the role level.
  • For read/write use, grant only the specific INSERT/UPDATE/DELETE privileges required, scoped to the necessary schemas and tables.
  • Combining a minimal-privilege role (database-enforced) with the blocklist (application-enforced) gives you defense in depth: even if a query slips past the blocklist, the role's privileges still bound what it can do.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-101-aws/

    Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    2 versions recorded. The original is kept in full — nothing is overwritten.

    1. v2 imported change on current
    2. v1 as first published on

    Provenance

    Organization
    Amazon Web Services — imported from official source
    Official source
    https://aws.amazon.com/security/security-bulletins/feed/ RSS
    Imported
    September 15, 2026 20:57
    Versions
    2 recorded
    Identity
    f91926ec56d6d7fde8ce69e8c06abb63033cedd7

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.