Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Windows-MCP unauthenticated HTTP control plane allowed arbitrary PowerShell execution

Versions of the open-source Windows-MCP server before 0.7.5 exposed the MCP control plane over HTTP without authentication and with wildcard CORS, allowing attackers from arbitrary origins or non-browser clients to invoke a PowerShell tool and run commands as the user running Windows-MCP. The issue was fixed in version 0.7.5.

Disclosed 17 June 2026 · Record updated 13 September 2026

Impact

Remote attackers could reach the unauthenticated MCP control plane and achieve arbitrary PowerShell command execution as the Windows user running Windows-MCP.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48989