CVE-2026-33980
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP tool handlers: `get_table_schema`, `sample_table_data`, and `get_table_details`. The `table_name` parameter is interpolated directly into KQL queries via f-strings without any validation or sanitization, allowing an attacker (or a prompt-injected AI agent) to execute arbitrary KQL queries against the Azure Data Explorer cluster. Commit 0abe0ee55279e111281076393e5e966335fffd30 patches the issue.
Published:Mar 27, 2026
Last Modified:Apr 22, 2026
EPS:Mar 27, 2026
EPSS Score:0.00052
CVSS Score:8.3
Affected Products
Vendor
Product
Action
Vendor
Pab1it0
Product
Adx-mcp-server
Pab1it0
Adx-mcp-server
Vendor
Pab1it0
Product
Azure Data Explorer Mcp Server
Pab1it0
Azure Data Explorer Mcp Server
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
