CVE-2026-107824
Received
Published: 09 Oct 2026, 17:45
Last modified:09 Oct 2026, 17:45
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.3 CRITICAL
v4.0 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
09 Oct 2026, 17:45
Published
Vulnerability first disclosed
Description
x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.
CVSS Metrics
- v4.0•CRITICAL•Score: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- v4.0•CRITICAL•Score: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Techniques & Countermeasures
- CWE-306•Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Affected Systems
- duty1g•x64dbg-mcp-server
< 1.1
References (6)
- https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-4478-h5jv-647m
- https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-jgj3-97w2-9v9r
- https://github.com/duty1g/x64dbg-mcp-server/commit/1aad0f88b9c27233d11dbccf08ca415eb5f49203
- https://github.com/duty1g/x64dbg-mcp-server/commit/e1daba0038959f88d25ff3376b2a7f922ffeb448
- https://github.com/duty1g/x64dbg-mcp-server/releases/tag/1.0
- https://github.com/duty1g/x64dbg-mcp-server/releases/tag/v1.1