CVE-2026-48989EPSS p31.3%
CVE-2026-48989CVE-2026-48989
Description
Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP modes exposed the MCP control plane without authentication while enabling wildcard CORS (allow_origins=*, allow_methods=*, allow_headers=*). Because the same server also exposed a PowerShell tool that executes caller-controlled commands as the Windows user running Windows-MCP, attackers could reach the control plane from arbitrary origins or non-browser clients and achieve arbitrary PowerShell execution. This issue was fixed in version 0.7.5.
Scoring
| EPSS | 0.40% probability of exploitation · percentile 31.3% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-18 |