High SEVERITY — Vulnerability

CVE-2026-48989 — Windows-MCP is an open-source project that integrates AI agents with Windows.

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clien

Platform
Windows Server
CVE Record
CVE-2026-48989
CVSS Score
8.9/10
Published
17 June 2026
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5.

Assessment

  • CVE: CVE-2026-48989
  • CVSS base score: 8.9
  • Vector: CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:H\/VI:H\/VA:H\/SC:N\/SI:N\/SA:N\/E:P\/CR:X\/IR:X\/AR:X\/MAV:X\/MAC:X\/MAT:X\/MPR:X\/MUI:X\/MVC:X\/MVI:X\/MVA:X\/MSC:X\/MSI:X\/MSA:X\/S:X\/AU:X\/R:X\/V:X\/RE:X\/U:X
  • Source: [NVD record](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-48989)

References

  • [github.com](https:\/\/github.com\/CursorTouch\/Windows-MCP\/releases\/tag\/v0.7.5)
  • [github.com](https:\/\/github.com\/CursorTouch\/Windows-MCP\/security\/advisories\/GHSA-vrxg-gm77-7q5g)

Actions

  • Validate affected systems in inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until the patch is applied

Windows Server — Related Advisories

VIEW ALL →