CVE-2026-48989
Received Received - Intake
Windows-MCP Pre-0.7.5 Unauthenticated PowerShell Command Execution

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: GitHub, Inc.

Description
Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Windows-MCP versions prior to 0.7.5, where certain HTTP modes exposed the MCP control plane without requiring authentication while allowing wildcard CORS settings (allowing any origin, method, and headers). Because the same server also exposed a PowerShell tool that executes commands controlled by the caller as the Windows user running Windows-MCP, attackers could exploit this to reach the control plane from any origin or non-browser client and execute arbitrary PowerShell commands.

Impact Analysis

The vulnerability allows attackers to execute arbitrary PowerShell commands on the affected system with the privileges of the Windows user running Windows-MCP. This can lead to unauthorized control over the system, potentially resulting in data theft, system compromise, or further attacks within the network.

Mitigation Strategies

To mitigate this vulnerability, upgrade Windows-MCP to version 0.7.5 or later, where the issue has been fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart