CRITICAL
doobidoo
CVE published 2026-08-14
CVE-2026-50027
CVE-2026-50027 is a critical vulnerability in the mcp-memory-service, a semantic memory layer for AI applications. The vulnerability allows unauthenticated remote attackers to upload, retrieve, and delete memories without supplying any credentials. This is because all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configur [truncated]