2 vulnerabilities across 2 products scored HIGH or above on June 13, 2026.
- HIGH: 2
[HIGH] google/mcp_toolbox_for_databases
1 CVE | CVSS 4.0: 9.4 | AAS 9.5
cpe:2.3:a:google:mcp_toolbox_for_databases:*:*:*:*:*:*:*:*(< 0.25.0)
Google’s MCP Toolbox for Databases versions before v0.25.0 are vulnerable to DNS rebinding attacks due to missing validation of the Origin header’s host portion (CVE-2026-11624, CVSS 9.4). Teams operating MCP server instances must upgrade to v0.25.0 and configure the new –allowed-hosts flag to enforce strict access controls. While exploitation remains theoretical, this vulnerability could allow attackers to bypass network boundaries and execute commands against vulnerable servers.
- CVE-2026-11624 (CVSS 4.0: 9.4)
[HIGH] nefteprodukttekhnika_llc/buk_ts-g_gas_station_automation_system
1 CVE | CVSS 4.0: 9.3 | AAS 9.2
cpe:2.3:a:nefteprodukttekhnika:buk_ts-g_gas_station_automation_system:*:*:*:*:*:*:*:*(>= 2.9.1, < 2.10.3)
Nefteprodukttekhnika’s BUK TS-G Gas Station Automation System versions 2.9.1 through 2.10.2 on Linux contain an authentication bypass vulnerability (CVE-2026-12183, CVSS 9.3) that grants unauthenticated administrative access. The /php/ajax-login.php endpoint accepts arbitrary credentials and returns administrator privileges without server-side session validation, allowing attackers to fully compromise gas station operations. Organizations deploying this automation system must immediately upgrade to a patched version and restrict network access to the web interface.
- CVE-2026-12183 (CVSS 4.0: 9.3)