Bug Hunter Exposes Three Serious MCP Database Flaws — One Vendor Refuses to Patch
If you’re running AI agents with MCP database connections, you need to read this now. A security researcher has uncovered three serious vulnerabilities in MCP database integrations affecting Apache and Alibaba database products. Apache patched their vulnerability. The other vendor declined to fix, leaving a known, unpatched flaw actively exposing any agent using that integration. The Register reported the findings on May 13, 2026. What Was Found The researcher identified three critical flaws in MCP server implementations used to connect AI agents to databases. The specific vulnerability classes have not been fully disclosed to avoid giving attackers a roadmap before defenders can patch — this is standard responsible disclosure practice. What is confirmed: ...