Summary
CVE-2026-50027 is a missing-authentication vulnerability (CWE-306) in mcp-memory-service, a Python-based memory storage server for the Model Context Protocol. The Document API endpoints under /api/documents/* are exposed without any authentication check, even when the server owner has configured an API key or OAuth. This flaw carries a CRITICAL CVSS v3.1 score of 9.8, as it allows a fully unauthenticated remote attacker to read, write, and delete stored memory data.
Technical details
- Root cause: The
documents.pyrouter is instantiated without a router-leveldependencies=parameter and does not importDepends, so no authentication dependency is applied to any route it defines. - Trigger conditions: The affected server exposes the Document API over the network; no credentials, session, or user interaction are required to reach the vulnerable routes, regardless of whether an API key or OAuth is configured for the rest of the application.
- Attack vector: Network — an attacker sends unauthenticated HTTP requests directly to the exposed endpoints (
POST /upload,POST /batch-upload,GET /history,GET /search-content/{upload_id},DELETE /remove/{upload_id},DELETE /remove-by-tags). - Impact: Confidentiality, integrity, and availability are all fully compromised — attackers can exfiltrate stored document content, inject arbitrary content into the memory store, and permanently delete legitimate stored memories. The parallel
/api/memoriesendpoints correctly enforce authentication, making this an inconsistent authorization boundary specific to the Document API.
Affected software
- doobidoo/mcp-memory-service versions prior to 10.67.1
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade mcp-memory-service to version 10.67.1 or later, where authentication is enforced on the Document API endpoints.
- If immediate patching is not possible: Restrict network exposure of the service (bind to localhost only or place it behind a network-level access control), and do not expose
/api/documents/*routes to untrusted networks until patched.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
MCP Memory Service - Dashboard,MCP Memory Service v(version)

