CVE-2026-33980 is a Kusto Query Language (KQL) injection vulnerability in Azure Data Explorer MCP Server affecting versions up to and including 0.1.1. The flaw exists in the MCP tool handlers get_table_schema, sample_table_data, and get_table_details, where the table_name parameter is inserted directly into KQL statements using Python f-strings without validation or sanitization. Because untrusted input is embedded into query text, an attacker can manipulate the intended query structure and cause the server to execute arbitrary KQL queries against the connected Azure Data Explorer (ADX/Kusto) cluster.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
get_table_schema, sample_table_data, and get_table_details), especially where requests may be influenced by untrusted users or prompt-injected agents. Enforce least-privilege on the Azure Data Explorer identity used by the MCP server so arbitrary query execution has minimal reach. Add server-side validation to permit only expected table names or identifier patterns, monitor for anomalous KQL activity originating from the MCP server, and isolate the service from untrusted prompting workflows until patched.Patch, then assume compromise.
0abe0ee55279e111281076393e5e966335fffd30. The vulnerable code should be replaced with safe query construction that does not directly interpolate untrusted table_name input into KQL strings. Apply strict allowlisting or validation for table identifiers, and ensure query-building logic treats user-supplied values as data rather than executable query syntax.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept for CVE-2026-33980 affecting adx-mcp-server. It contains two files: a README describing the vulnerability, impact, and affected upstream code paths, and a single Python script (`poc.py`) that demonstrates how malicious `table_name` values alter the final KQL sent by vulnerable MCP tools. The exploit is not a full end-to-end weaponized client; it is a demonstrative PoC that prints crafted KQL queries and example MCP tool-call JSON. The core capability is KQL injection through unsanitized interpolation of `table_name` into three upstream query templates: `f"{table_name} | getschema"`, `f"{table_name} | sample {sample_size}"`, and `f".show table {table_name} details"`. By embedding KQL operators, comments (`//`), or newline-separated management commands, an attacker can bypass the intended semantics of metadata/sample tools. Demonstrated outcomes include reading arbitrary columns from other tables, running arbitrary analytics queries, and issuing destructive commands such as `.drop table` if the server identity has sufficient privileges. There are no hardcoded network callbacks, C2 endpoints, or external exfiltration destinations in the PoC itself. The repository instead fingerprints the vulnerable upstream component (`src/adx_mcp_server/server.py`) and references advisory/NVD URLs. Operationally, this is a cloud-focused exploit against Azure Data Explorer access exposed through an MCP server, with an additional trust-boundary angle: supposedly safe auto-approved tools can be abused to achieve effects similar to a raw query execution tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.