HTTP Authentication Bypass in x64dbg-MCP Server Plugin by Duty1G
CVE-2026-107824

9.3CRITICAL

Key Information:

Vendor

Duty1g

Vendor
CVE Published:
9 October 2026

What is CVE-2026-107824?

The x64dbg-MCP Server is a plugin that should offer secure functionality for debugging over HTTP. However, prior to version 1.1, it lacked proper authentication, allowing any unauthenticated network client to access its services. By default, the server listens on all network interfaces (0.0.0.0) and exposes critical debugging features on ports 9094 and 9095. This allows attackers to execute arbitrary x64dbg commands, manipulate processes, access sensitive memory data, and write files to any directory within the server’s file system. This significant security flaw has been mitigated in the latest release, version 1.1.

Affected Version(s)

x64dbg-mcp-server < 1.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.