CVE-2026-107824
Received Received - Intake

Unauthenticated Remote Code Execution in x64dbg-MCP Server

Vulnerability report for CVE-2026-107824, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
duty1g x64dbg-mcp-server < 1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects x64dbg-MCP Server versions prior to 1.1. The server exposes all debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Unauthenticated network clients can reach the default ports (9094 for x64 or 9095 for x32) and execute arbitrary x64dbg commands, attach to processes, read/write memory, and write files to arbitrary paths.

Detection Guidance

Check if the x64dbg-MCP Server is running on default ports 9094 (x64) or 9095 (x32) by using commands like 'netstat -tuln | grep 9094' or 'ss -tuln | grep 9094' on Linux. Verify if the server is bound to 0.0.0.0, which indicates exposure to all network interfaces.

Impact Analysis

An attacker could gain full control over the x64dbg debugger, allowing them to execute malicious commands, manipulate running processes, read or write sensitive memory, or write arbitrary files to the system. This could lead to system compromise or data theft if the debugger is used in a security-sensitive context.

Compliance Impact

The vulnerability allows unauthenticated remote access to execute arbitrary commands, read/write memory, and write files, which could lead to unauthorized data access or modification. This violates GDPR's data protection principles (Article 5) and HIPAA's security requirements (45 CFR Β§ 164.308) by enabling unauthorized access to sensitive debuggee data.

Mitigation Strategies

Upgrade to version 1.1 or later to enforce authentication and fix the unauthenticated access issue. If upgrading is not possible, restrict the server to bind only to 127.0.0.1 in the configuration to limit exposure. Ensure Bearer token authentication is enabled and all clients use valid tokens for requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107824. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart