NONE · 0

CVE-2026-48989

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcar...

Vulnerability Description

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-48989?

CVE-2026-48989 is a documented vulnerability. Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcar...

How severe is CVE-2026-48989?

CVSS scoring is not yet available for CVE-2026-48989. Check NVD for updates.

Is there a patch for CVE-2026-48989?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.