Executive brief
AWS mcp-gateway-registry is a service used to manage cluster and gateway configurations in cloud environments. The metrics-service retention policy subsystem contains an authenticated SQL injection vulnerability that allows a user with valid credentials to execute arbitrary SQL queries and potentially read or modify sensitive operational data stored in the metrics database.
Technical details
The vulnerability is a SQL injection flaw in the retention policy subsystem of the metrics-service component within mcp-gateway-registry. The vulnerability exists in the handling of user-supplied input to retention policy configuration parameters, where input validation is insufficient or missing. An attacker must be authenticated to exploit this vulnerability, reducing the attack surface to valid users or compromised accounts. By crafting malicious SQL payloads in retention policy fields, an attacker can execute arbitrary SQL commands against the metrics database, potentially leading to unauthorized data access, modification, or deletion of metrics and monitoring data. Patches or updates from AWS should be applied to affected versions of mcp-gateway-registry.
Affected products
- AWS mcp-gateway-registry <UNKNOWN>
Timeline
- 2026-09-22: disclosed: CVE-2026-14471 publicly disclosed