---
title: "MCPJam Inspector Remote Code Execution - CVE-2026-23744"
description: "CVE-2026-23744 is a critical RCE in MCPJam Inspector ≤ 1.4.2: it binds 0.0.0.0 and a crafted request triggers an MCP server install and code execution."
url: "https://anomity.ai/blog/mcpjam-inspector-rce-cve-2026-23744/"
source: html
---

On this page

- What happened
- Why this is an agentic-endpoint risk
- How Anomity surfaces and governs it
- What to check across your fleet
- Frequently asked questions

[← Back to blog](https://anomity.ai/blog/)

- Home

- Blog

- MCPJam Inspector Remote Code Execution - CVE-2026-23744

![Anomity robot illustrating MCPJam Inspector Remote Code Execution - CVE-2026-23744]

Advisory Critical

# MCPJam Inspector Remote Code Execution - CVE-2026-23744

Anomity Research
Anomity Threat Research
·
May 28, 2026
·
2 min read

Share: Copied

MCP Server Security · Critical · CVE-2026-23744 · May 28, 2026

Affected MCPJam Inspector ≤ 1.4.2 (patched in 1.4.3)

## What happened

**CVE-2026-23744** is a critical remote code execution vulnerability in MCPJam Inspector, a developer tool for inspecting Model Context Protocol servers, affecting versions **1.4.2 and earlier**. By default the Inspector listens on all network interfaces (`0.0.0.0`), so it is reachable beyond localhost. An unauthenticated attacker who can reach that port can send a specially crafted HTTP request that triggers installation of an MCP server and execution of arbitrary code on the host. The issue was fixed in **1.4.3**.

## Why this is an agentic-endpoint risk

MCP inspectors and utilities live on developer laptops next to the agents they debug. A flaw like this turns a convenience tool into an unauthenticated foothold on a managed endpoint - and because it is an AI-tooling process binding a local port, it is exactly the kind of artifact that [traditional controls were never designed to see](https://anomity.ai/#compare). It is a textbook case of [shadow AI on the endpoint](https://anomity.ai/blog/ai-agents-are-the-new-shadow-it/): installed bottom-up, network-reachable, and unreviewed.

## How Anomity surfaces and governs it

Anomity inventories AI tooling - including MCP servers, inspectors, and the [eight AI artifact types](https://anomity.ai/#features) - on every managed endpoint, and surfaces the exact version in use, so finding every vulnerable MCPJam Inspector becomes one query rather than a fleet-wide hunt. It flags instances that bind a network transport without authentication, and on agents that expose a hook it applies [runtime governance](https://anomity.ai/#runtime-governance) - allowing, denying, or logging each MCP tool call before it runs. Every install and version change is captured in the [90-day audit trail](https://anomity.ai/#outcomes).

## What to check across your fleet

- Inventory every endpoint for MCPJam Inspector and record its version; upgrade anything ≤ 1.4.2 to 1.4.3 .
- Identify any MCP tool or inspector bound to 0.0.0.0 or a non-loopback interface.
- Confirm developer tools are not exposed beyond localhost on shared networks.
- Add a policy: MCP inspectors and servers must require transport authentication.
- Review the audit trail for recent MCP server installs triggered outside normal workflows.

This advisory is part of our [MCP Server Security guide](https://anomity.ai/blog/mcp-server-security-complete-guide/). To see your own MCP posture, [book a 30-minute demo](https://anomity.ai/#early-access).

Share: Copied

## Frequently asked questions

Am I affected by CVE-2026-23744?
You are exposed if any developer endpoint runs MCPJam Inspector at version 1.4.2 or earlier, especially on a shared or reachable network, since the tool binds to all interfaces (0.0.0.0) by default. Upgrading to 1.4.3 remediates the flaw. The practical problem is knowing where the tool is installed in the first place - that requires a fleet inventory of AI tooling.

What does the vulnerability allow?
An unauthenticated attacker who can reach the Inspector's port can send a crafted HTTP request that triggers installation of an MCP server and execution of arbitrary code on the host, with the privileges of the user running the Inspector.

How does Anomity help with CVE-2026-23744?
Anomity inventories MCP tooling - including inspectors and developer utilities - across every managed endpoint, surfaces the version in use, and flags instances that bind a network transport without authentication. On agents that expose a hook, it can deny the MCP tool calls a compromised inspector would attempt before they run.

## Related

[Advisory Critical ### mcp-atlassian HTTP Auth Bypass Falls Back to Global Credentials - CVE-2026-77254 CVE-2026-77254 (CVSS 9.1): unauthenticated HTTP MCP requests to mcp-atlassian below 0.22.0 fall through to globally configured Jira/Confluence credentials. Sibling CVE-2026-77244 (CVSS 10.0) accepts any non-empty token. Anomity Research · Sep 28, 2026 · CVE-2026-77254 (CVSS 9.1, GHSA-vc8m-84rp-53hx); sibling CVE-2026-77244 (CVSS 10.0, GHSA-wrhw-j3f9-8vc6)](https://anomity.ai/blog/mcp-atlassian-http-auth-bypass-global-credentials-cve-2026-77254/)

[Advisory Critical ### GitLab MCP CVE-2026-61568 - Streamable HTTP DNS Rebinding to Localhost CVE-2026-61568 (CVSS 9.6): @zereight/mcp-gitlab Streamable HTTP skipped SDK DNS-rebinding Host/Origin allowlists on loopback - fixed in 2.1.30. Anomity Research · Sep 21, 2026 · CVE-2026-61568 (CVSS 9.6, GHSA-vmp7-252j-cwp7)](https://anomity.ai/blog/mcp-gitlab-streamable-http-dns-rebinding-cve-2026-61568/)

[Advisory Critical ### MySQL MCP Server CVE-2026-59971 - Unauthenticated SQL via SSE DNS Rebinding CVE-2026-59971 (CVSS 10.0): mysql-mcp-server SSE mode skipped Host/Origin DNS-rebinding protection, bound 0.0.0.0 with no auth - unauthenticated SQL until 0.4.2. Anomity Research · Sep 21, 2026 · CVE-2026-59971 (CVSS 10.0, GHSA-rqfv-2mw9-78g2)](https://anomity.ai/blog/mysql-mcp-server-sse-dns-rebinding-unauth-sql-cve-2026-59971/)

## Structured data

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "MCPJam Inspector Remote Code Execution - CVE-2026-23744",
  "description": "CVE-2026-23744 is a critical RCE in MCPJam Inspector ≤ 1.4.2: it binds 0.0.0.0 and a crafted request triggers an MCP server install and code execution.",
  "datePublished": "2026-05-28",
  "dateModified": "2026-05-28",
  "author": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ]
  },
  "publisher": {
    "@type": "Organization",
    "name": "Anomity",
    "url": "https://anomity.ai/",
    "sameAs": [
      "https://www.linkedin.com/company/anomity",
      "https://github.com/Anomity-ai",
      "https://www.wikidata.org/wiki/Q140763940"
    ],
    "logo": {
      "@type": "ImageObject",
      "url": "https://anomity.ai/icon-512.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://anomity.ai/blog/mcpjam-inspector-rce-cve-2026-23744/"
  },
  "image": {
    "@type": "ImageObject",
    "url": "https://anomity.ai/assets/blog/covers/prompt-injection.jpg",
    "width": 1200,
    "height": 630
  },
  "articleSection": "MCP Server Security",
  "url": "https://anomity.ai/blog/mcpjam-inspector-rce-cve-2026-23744/",
  "keywords": "MCPJam Inspector RCE CVE-2026-23744, CVE-2026-23744, MCP, remote code execution, CVE-2026-23744, MCPJam Inspector"
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Am I affected by CVE-2026-23744?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "You are exposed if any developer endpoint runs MCPJam Inspector at version 1.4.2 or earlier, especially on a shared or reachable network, since the tool binds to all interfaces (0.0.0.0) by default. Upgrading to 1.4.3 remediates the flaw. The practical problem is knowing where the tool is installed in the first place - that requires a fleet inventory of AI tooling."
      }
    },
    {
      "@type": "Question",
      "name": "What does the vulnerability allow?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "An unauthenticated attacker who can reach the Inspector's port can send a crafted HTTP request that triggers installation of an MCP server and execution of arbitrary code on the host, with the privileges of the user running the Inspector."
      }
    },
    {
      "@type": "Question",
      "name": "How does Anomity help with CVE-2026-23744?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Anomity inventories MCP tooling - including inspectors and developer utilities - across every managed endpoint, surfaces the version in use, and flags instances that bind a network transport without authentication. On agents that expose a hook, it can deny the MCP tool calls a compromised inspector would attempt before they run."
      }
    }
  ]
}
```

```json
{
  "@context": "https://schema.org",
  "@type": "BreadcrumbList",
  "itemListElement": [
    {
      "@type": "ListItem",
      "position": 1,
      "name": "Home",
      "item": "https://anomity.ai/"
    },
    {
      "@type": "ListItem",
      "position": 2,
      "name": "Blog",
      "item": "https://anomity.ai/blog/"
    },
    {
      "@type": "ListItem",
      "position": 3,
      "name": "MCPJam Inspector Remote Code Execution - CVE-2026-23744",
      "item": "https://anomity.ai/blog/mcpjam-inspector-rce-cve-2026-23744/"
    }
  ]
}
```
