Authentication Bypass Vulnerability in mcp-memory-service by Doobidoo
CVE-2026-50027

9.8CRITICAL

Key Information:

Vendor

Doobidoo

Vendor
CVE Published:
14 August 2026

What is CVE-2026-50027?

The mcp-memory-service, a semantic memory layer for AI applications, has a significant vulnerability allowing unauthenticated access to all HTTP routes under /api/documents/*. This lack of proper authentication means that attackers can upload arbitrary content, retrieve stored document content, and delete memories belonging to authenticated users without needing to provide any credentials. This security gap presents a critical inconsistency in authentication enforcement, especially since similar endpoints in the service correctly implement authentication checks. The issue has been addressed in version 10.67.1.

Affected Version(s)

mcp-memory-service < 10.67.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.