What is CVE-2026-50027?
CVE-2026-50027 affects mcp-memory-service, a semantic memory layer for AI applications. Prior to version 10.67.1, all HTTP routes under /api/documents/* lack authentication even when an API key or OAuth is configured, allowing unauthenticated remote access. Immediate update to version 10.67.1 or later is required to mitigate the issue.
Azərbaycanca: CVE-2026-50027 mcp-memory-service AI tətbiqetmələri üçün semantik yaddaş qatıdır. 10.67.1 versiyasından əvvəl, API açarı (MCP_API_KEY) və ya OAuth konfiqurasiya olunsa belə, /api/documents/* altındakı HTTP route-lar autentifikasiyasız təqdim edilir. İstismar uzaqdan icazəsiz girişə imkan verir, dərhal 10.67.1 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which product does CVE-2026-50027 affect?
CVE-2026-50027 affects mcp-memory-service, a semantic memory layer for AI applications.
What action is recommended to remediate this vulnerability?
Immediate update to version 10.67.1 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.