2 vulnerabilities across 2 products scored HIGH or above on June 13, 2026.

  • HIGH: 2

[HIGH] google/mcp_toolbox_for_databases

1 CVE | CVSS 4.0: 9.4 | AAS 9.5

  • cpe:2.3:a:google:mcp_toolbox_for_databases:*:*:*:*:*:*:*:* (< 0.25.0)

Google’s MCP Toolbox for Databases versions before v0.25.0 are vulnerable to DNS rebinding attacks due to missing validation of the Origin header’s host portion (CVE-2026-11624, CVSS 9.4). Teams operating MCP server instances must upgrade to v0.25.0 and configure the new –allowed-hosts flag to enforce strict access controls. While exploitation remains theoretical, this vulnerability could allow attackers to bypass network boundaries and execute commands against vulnerable servers.

Vendor Advisory


[HIGH] nefteprodukttekhnika_llc/buk_ts-g_gas_station_automation_system

1 CVE | CVSS 4.0: 9.3 | AAS 9.2

  • cpe:2.3:a:nefteprodukttekhnika:buk_ts-g_gas_station_automation_system:*:*:*:*:*:*:*:* (>= 2.9.1, < 2.10.3)

Nefteprodukttekhnika’s BUK TS-G Gas Station Automation System versions 2.9.1 through 2.10.2 on Linux contain an authentication bypass vulnerability (CVE-2026-12183, CVSS 9.3) that grants unauthenticated administrative access. The /php/ajax-login.php endpoint accepts arbitrary credentials and returns administrator privileges without server-side session validation, allowing attackers to fully compromise gas station operations. Organizations deploying this automation system must immediately upgrade to a patched version and restrict network access to the web interface.

Vendor Advisory