Vulnerability  ·  2026-08-15

mcp-memory-service — unauthenticated document API bypasses configured MCP authentication

VulnerabilityHigh impactGlobalCVE-2026-50027
NVD published CVE-2026-50027 (CVSS 9.8, Critical) on 2026-08-14. mcp-memory-service, a semantic memory layer MCP server for AI applications, exposed all /api/documents/* routes without authentication enforcement even when API keys or OAuth were configured, prior to 10.67.1.
MCP memory servers hold persistent context and potentially sensitive data for AI agents across sessions; a total authentication bypass allows any remote attacker to read or corrupt an agent's long-term memory store, undermining trust in AI-agent decision-making built on that memory.
All HTTP routes under /api/documents/* are served without any authentication dependency even when MCP_API_KEY or OAuth is configured, allowing an unauthenticated remote attacker to read/manipulate stored semantic memory documents
mcp-memory-service < 10.67.1
Upgrade to mcp-memory-service 10.67.1 or later
GitHub Advisory GHSA-84hp-mqvj-3p8hNVD CVE-2026-50027
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →