CVE-2026-40576Disclosure

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the network can read, write, and overwrite arbitrary files on the host filesystem by supplying crafted filepath arguments to any of the 25 exposed MCP tool handlers. The server is intended to confine file operations to a directory set by the EXCEL_FILES_PATH environment variable. The function responsible for enforcing this boundary — get_excel_path() — fails to do so due to two independent flaws: it passes absolute paths through without any check, and it joins relative paths without resolving or validating the result. Combined with zero authentication on the default network-facing transport and a default bind address of 0.0.0.0 (all interfaces), this allows trivial remote exploitation. This vulnerability is fixed in 0.1.8.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-21); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-16: 1Mentions · 2026-04-21: 3Mentions · 2026-06-19: 1PoC Mentioned / Linked · 2026-04-21: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-21: 204-1604-2106-19
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-161
Patch1
2026-04-213
Disclosure2General1
2026-06-191
Disclosure1
Full discourse5 posts
  • Loktar 🇺🇸@loktar00
    General

    Anthropic called this flaw 'expected behavior' last week.... today CVE-2026-40576 landed. Thats how every 'expected behavior' post ages, every single time https://x.com/MosheTov/status/2044869962980827529

    Post summary

    Anthropic labeled CVE-2026-40576 as 'expected behavior' and the CVE has been published, but the excerpt offers no technical details, exploit code, or mitigation information.

    200711.1K
    3.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    09:11 UTC: CVE-2026-40576 disclosed. The Protocol That Trusted Everyone: MCP's Architecture-Level Security Crisis, 200,000 Exposed Instances, and the AI Supp

    Post summary

    A new vulnerability (CVE-2026-40576) was announced, highlighting an architecture-level security crisis with 200,000 exposed instances.

    1000040
    294 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40576 excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and includin… https://www.cve.org/CVERecord?id=CVE-2026-40576

    Post summary

    The text discloses a path traversal vulnerability in excel-mcp-server, but does not mention any PoC, exploit code, active exploitation, or patch information.

    00010160
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40576: Im... Zero-auth path traversal + 0.0.0.0 bind = instant RCE playground for anyone who can reach your Excel server's network port. #PathTraversal #RCE #MCP. https://zerodaysignal.com/vulnerability/CVE-2026-40576 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑40576, detailing a zero‑auth path traversal that allows RCE on Excel servers, with a link likely pointing to further PoC or exploit information, but reports no patches, active attacks, or debunking.

    0001079
    218 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A path traversal flaw impacts `excel-mcp-server`, identified as CVE-2026-40576. This can enable unauthorized file access. Review systems and apply patches as they become available. #PathTraversal #CVE #InfoSec https://www.pulsepatch.io/posts/cve-2026-40576-excel-mcp-server-path-traversal

    Post summary

    A path traversal vulnerability in excel‑mcp‑server (CVE-2026-40576) has been disclosed, with a call to review and apply future patches.

    0001069
    12 followersView on X

Explore more