Authentication Bypass Vulnerability in mcp-memory-service by Doobidoo
CVE-2026-50027
9.8CRITICAL
What is CVE-2026-50027?
The mcp-memory-service, a semantic memory layer for AI applications, has a significant vulnerability allowing unauthenticated access to all HTTP routes under /api/documents/*. This lack of proper authentication means that attackers can upload arbitrary content, retrieve stored document content, and delete memories belonging to authenticated users without needing to provide any credentials. This security gap presents a critical inconsistency in authentication enforcement, especially since similar endpoints in the service correctly implement authentication checks. The issue has been addressed in version 10.67.1.
Affected Version(s)
mcp-memory-service < 10.67.1
