OAuth Misconfiguration in mcp-memory-service by Doobidoo
CVE-2026-49291
8.1HIGH
What is CVE-2026-49291?
The mcp-memory-service, utilized for enhancing AI applications, contains a vulnerabilities prior to version 10.65.3, where the HTTP MCP JSON-RPC endpoint at /mcp allows unauthorized access. This issue occurs because the endpoint only requires OAuth read scope for all requests. Consequently, attackers can exploit this misconfiguration to perform sensitive operations like store_memory and delete_memory, which are intended to require a write scope. Version 10.65.3 has been released to rectify this security oversight, ensuring that proper scope checks are enforced.
Affected Version(s)
mcp-memory-service < 10.65.3
