CVE-2026-33980: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33980 is a KQL (Kusto Query Language) injection vulnerability in the Azure Data Explorer MCP Server (adx-mcp-server), a Model Context Protocol server enabling AI assistants to interact with Azure Data Explorer (ADX/Kusto) databases. Versions up to and including 0.1.1 (pip package) are affected across three MCP tool handlers: get_table_schema, sample_table_data, and get_table_details. The vulnerability was published on March 25, 2026, and assigned CVE-2026-33980 with GHSA ID GHSA-vphc-468g-8rfp. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is CWE-943 (Improper Neutralization of Special Elements in Data Query Logic): the table_name parameter is interpolated directly into KQL query strings via Python f-strings without any validation or sanitization. For example, get_table_schema constructs f"{table_name} | getschema", sample_table_data constructs f"{table_name} | sample {sample_size}", and get_table_details constructs f".show table {table_name} details". KQL's pipe operator (|) enables query chaining, // enables comment injection to suppress trailing query clauses, and newlines enable injection of management commands (e.g., .drop table). Critically, the three vulnerable tools are presented as safe metadata-inspection tools, and MCP clients may auto-approve them while requiring confirmation for the explicit execute_query tool — meaning injection bypasses this trust boundary. A public PoC with concrete payloads is available in the security advisory (Security Advisory).

Impact

An authenticated attacker with low privileges can execute arbitrary KQL queries against the Azure Data Explorer cluster, resulting in high confidentiality and integrity impact. Exploitation enables reading sensitive data from any accessible table (e.g., credentials, secrets), modifying or deleting data via management commands such as .drop table, and bypassing the MCP client's trust model for tool authorization. Availability impact is rated Low, as destructive management commands could cause data loss but not necessarily full service disruption (GitHub Advisory, Security Advisory).

Exploitability

A proof-of-concept exploit with specific malicious table_name payloads is publicly available in the GitHub security advisory and has also been indexed on Sploitus. A separate PoC repository (github.com/romain-deperne/CVE-2026-33980) was published in late April 2026. There is no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.046% per Feedly), placing it in the 5th percentile for exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Security Advisory).

Exploitation steps

  1. Identify target: Locate a deployment of adx-mcp-server (pip package adx-mcp-server <= 0.1.1) accessible over the network, connected to an Azure Data Explorer cluster.
  2. Obtain low-privilege access: Authenticate to the MCP server with any valid low-privilege account, as the vulnerability requires only PR:L (low privileges required).
  3. Invoke a vulnerable tool with an injected payload: Call the get_table_schema tool with a crafted table_name to exfiltrate data:
{
  "name": "get_table_schema",
  "arguments": {
    "table_name": "sensitive_data | project Secret, Password | take 100 //"
  }
}

This results in the KQL query: sensitive_data | project Secret, Password | take 100 // | getschema — the // comments out | getschema, executing the data exfiltration query instead. 4. Execute destructive management commands: Call get_table_details with a newline-injected payload to run management commands:

{
  "name": "get_table_details",
  "arguments": {
    "table_name": "users details\n.drop table critical_data"
  }
}

This results in two KQL statements: .show table users details followed by .drop table critical_data. 5. Exfiltrate or manipulate data: Review query results returned by the MCP server to harvest sensitive data, or confirm destructive operations succeeded via subsequent metadata queries (Security Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous MCP tool calls to get_table_schema, sample_table_data, or get_table_details with table_name values containing pipe characters (|), newlines (\n), double slashes (//), semicolons (;), or other non-alphanumeric/non-underscore/non-dot characters.
  • Logs: Azure Data Explorer query logs showing KQL queries with chained operators (e.g., | project, | take) or management commands (e.g., .drop table, .alter table) originating from the MCP server's service principal or connection identity, especially when invoked via the metadata tool handlers rather than execute_query.
  • Application Logs: MCP server logs recording table_name parameter values that do not match simple identifier patterns (letters, digits, underscores, dots); error messages from the patched version indicating "Invalid table name" rejections may indicate attempted exploitation post-patch.
  • Azure ADX Audit: Unexpected .drop, .alter, or .delete management commands in Azure Data Explorer activity logs attributed to the MCP server's identity (Security Advisory).

Mitigation and workarounds

The fix is available in commit 0abe0ee55279e111281076393e5e966335fffd30, which introduces a validate_table_name() function using a strict regex allowlist (^[a-zA-Z_][a-zA-Z0-9_]*(\.[a-zA-Z_][a-zA-Z0-9_]*)*$) and a validate_sample_size() function for positive integer enforcement. Users should update to a version of adx-mcp-server that includes this commit. As a workaround prior to patching, restrict network access to the MCP server to trusted clients only, enforce strong authentication controls, and monitor Azure Data Explorer query logs for anomalous activity. Consider applying Azure Data Explorer RBAC to limit the permissions of the MCP server's service identity to read-only where possible (Patch Commit, Security Advisory).

Community reactions

The vulnerability was reported by security researcher romain-deperne, who also published a dedicated PoC repository. The advisory was noted on Mastodon (via @thehackerwire) and Bluesky shortly after disclosure, and was indexed by multiple vulnerability tracking platforms including VulDB, CVEFeed, and Sploitus. Community discussion highlighted the novel attack surface of MCP servers as AI-adjacent infrastructure and the risk of prompt-injected AI agents exploiting injection flaws in tools presented as "safe" (Security Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management