Missing Authentication for Critical Function Affecting windows-mcp package, versions [,0.7.5)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.4% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-WINDOWSMCP-17660987
  • published28 Jun 2026
  • disclosed18 Jun 2026
  • creditUnknown

Introduced: 18 Jun 2026

CVE-2026-48989  (opens in a new tab)
CWE-306  (opens in a new tab)

How to fix?

Upgrade windows-mcp to version 0.7.5 or higher.

Overview

windows-mcp is a Lightweight MCP Server for interacting with Windows Operating System.

Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the HTTP transport process when authentication is not enforced and wildcard CORS is enabled. An attacker can execute arbitrary PowerShell commands as the Windows user running the application by sending requests from any origin or non-browser client.

CVSS Base Scores

version 4.0
version 3.1