HTTP Authentication Bypass in x64dbg-MCP Server Plugin by Duty1G
CVE-2026-107824
9.3CRITICAL
What is CVE-2026-107824?
The x64dbg-MCP Server is a plugin that should offer secure functionality for debugging over HTTP. However, prior to version 1.1, it lacked proper authentication, allowing any unauthenticated network client to access its services. By default, the server listens on all network interfaces (0.0.0.0) and exposes critical debugging features on ports 9094 and 9095. This allows attackers to execute arbitrary x64dbg commands, manipulate processes, access sensitive memory data, and write files to any directory within the server’s file system. This significant security flaw has been mitigated in the latest release, version 1.1.
Affected Version(s)
x64dbg-mcp-server < 1.1
