vulnerability · DiggingBeagle record
CVE-2026-48989
Windows-MCP unauthenticated HTTP control-plane vulnerability.
- Entity kind
- vulnerability
A relationship records context, not guilt, vulnerability or endorsement.
Record description
The issue was fixed in Windows-MCP 0.7.5 by changing CORS defaults and adding DNS-rebinding protection.
Cite this record
DiggingBeagle. “CVE-2026-48989.” https://diggingbeagle.com/entities/cve-2026-48989/
Citation guidance