CVE-2026-87911
Cybersecurity Classified by Officially
CVE-2026-87911 - Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
Bulletin ID: 2026-104-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/09/2026 12:30 PM PDT
awslabs.postgres-mcp-server is a python package that implements a Postgres MCP server. We found CVE-2026-87911, where an OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP server in its default read-only mode.
awslabs.postgres-mcp-server before 1.1.7, self-managed PostgreSQL deployment profile (PG_WIRE_PROTOCOL connection method) where the configured database role holds superuser or pg_execute_server_program.
This issue has been addressed in awslabs postgres-mcp-server (python package) version 1.1.7 in pypi.
The strongest control is to connect the MCP server using a dedicated Postgres role that has only the privileges it actually needs, so that the database itself enforces the boundary regardless of what SQL reaches it. In particular:
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-104-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
f7f64245a3266643e8774537e1fd4769f8941282