Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

mcp-memory-service authentication bypass in document endpoints

mcp-memory-service versions prior to 10.67.1 lack authentication on /api/documents/* endpoints, allowing unauthenticated attackers to read, write, and delete memory content despite configured API keys or OAuth.

Disclosed 14 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated remote attackers can upload arbitrary content, retrieve stored documents, and permanently delete user memories without credentials.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-50027