THREAT OPS › Threat News › [NVD] CVE-2026-50027 (CRITICAL 9.8) — mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauth
[NVD] CVE-2026-50027 (CRITICAL 9.8) — mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauth
CVE-2026-50027 CVSS: 9.8 CRITICAL Published: 2026-08-14T19:17:18.843
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload arbitrary con
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-50027cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-50027