Token Security researcher Ariel Simon, presenting at RSAC 2026, disclosed CVE-2026-23744 in MCPJam Inspector (≤ v1.4.2): the critical endpoint binds to 0.0.0.0 with no authentication, allowing a crafted HTTP request to install an arbitrary MCP server and execute code on the host with zero user interaction. The demonstrated kill chain chains this into full Azure tenant compromise via credential harvesting from the Azure MCP server. Patched in v1.4.3—anyone running MCPJam Inspector must upgrade immediately.