Description
x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Unauthenticated Debugger Access
Action: Immediate Patch
AI Analysis

Impact

x64dbg-MCP Server, a native Model Context Protocol plugin for x64dbg, exposes the full debugger functionality over HTTP and server-sent events. In versions prior to 1.1 the service listens on all network interfaces by default and does not require authentication. Any network client that can reach the listening ports (9094 for the 64‑bit build and 9095 for the 32‑bit build) can execute arbitrary debugger commands, attach to processes by PID, read or write debuggee memory, and write files to arbitrary paths. This allows an attacker to run arbitrary code with the privileges of the x64dbg process, effectively granting remote code execution. The weakness is identified as CWE‑306 (Missing Authentication for Critical Function).

Affected Systems

The affected product is the x64dbg-MCP Server plugin developed by duty1g. Versions before 1.1 expose the vulnerability; any deployment using 1.0 or older is affected. The service is bound to 0.0.0.0 by default unless explicitly configured otherwise.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is rated critical. The EPSS score is not available, but the lack of authentication and open network binding make exploitation straightforward for anyone who can reach the service. The vulnerability is not listed in CISA’s KEV catalog, but its high severity and ease of exploitation mean it should be treated with the highest priority. Attackers can launch the vulnerability remotely over the network without any special privileges on the host system.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MCP Server to version 1.1 or later, which removes the unauthenticated interface.
  • Reconfigure the MCP Server to bind only to localhost or a non‑public interface, and use firewall rules to block external access to ports 9094 and 9095.
  • If the debugging functionality is not required, disable or uninstall the MCP Server plugin entirely.

Generated by OpenCVE AI on October 9, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.
Title x64dbg-MCP Server exposes debugger operations to unauthenticated network clients
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:45:17.458Z

Reserved: 2026-10-08T21:23:59.824Z

Link: CVE-2026-107824

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:04.350

Modified: 2026-10-09T18:17:04.350

Link: CVE-2026-107824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function