Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-44830: Nocturne Memory MCP server auth bypass exposes agent memory

Nocturne Memory, a long-term memory server for MCP agents, bypassed Bearer token authentication for all HTTP requests when API_TOKEN was unset or empty; combined with default 0.0.0.0 binding and wildcard CORS, this exposed the full knowledge-graph read/write API to any LAN-reachable client, allowing attackers to alter entries that auto-load into agent sessions and achieve persistent prompt injection. Fixed in version 2.4.1.

Disclosed 27 May 2026 · Record updated 13 September 2026

Impact

Unauthenticated LAN-reachable attackers could read, write or delete all memory entries, including system://boot and core://* URIs that auto-load into downstream agent sessions, enabling persistent prompt injection.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44830