Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MemOS Authentication Bypass via Unset Internal Service Secret

MemOS fails to properly validate internal service requests when the INTERNAL_SERVICE_SECRET environment variable is unset, allowing unauthenticated remote attackers to bypass authentication and access admin API endpoints to mint, enumerate, and revoke API keys.

Disclosed 17 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated remote attackers can access admin API-key management endpoints and all data endpoints, including minting API keys for any user and generating a master key for persistent privileged access.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75110