mcp-memory-service authentication bypass in document endpoints
mcp-memory-service versions prior to 10.67.1 lack authentication on /api/documents/* endpoints, allowing unauthenticated attackers to read, write, and delete memory content despite configured API keys or OAuth.
Disclosed 14 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated remote attackers can upload arbitrary content, retrieve stored documents, and permanently delete user memories without credentials.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-50027
