CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope

Awslabs Postgres ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions < 1.1.7
Regions all
CVE IDs CVE-2026-85787
Migration Required Yes
Cost Impact Neutral
IaC Impact High

What This Means

For DevOps Teams

Update the awslabs postgres-mcp-server to version 1.1.7 and configure it to run with minimal-privilege Postgres roles to address the security vulnerability identified as CVE-2026-85787.

For Platform Teams

Deploy the updated awslabs postgres-mcp-server version 1.1.7 and integrate it with minimal-privilege Postgres roles to enhance security and data protection.

For Executives

Implement the upgrade to version 1.1.7 of awslabs postgres-mcp-server to mitigate the security risk posed by CVE-2026-85787 and ensure data integrity.

Source

View original AWS announcement โ†’

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.