CVE-2026-49291Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-20); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-19: 1Mentions · 2026-06-20: 2Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-20: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-20: 2Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 106-1906-2006-2606-27
Signal classification1 categories
Disclosure
5100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-202
Disclosure2
2026-06-261
Disclosure1
2026-06-271
Disclosure1
Full discourse5 posts
  • Mr. OS@ksg93rd
    Disclosure

    CVE-2026-49291: mcp-memory-service OAuth read-only clients can write/delete memories via MCP tools/call The advisory describes an OAuth scope check placed only at the /mcp JSON-RPC boundary: requests with read scope can still reach tools/call handlers that invoke mutating tools like storememory and deletememory, enabling state changes despite “read-only” authorization. #MCP #AgentSecurity #AISecurity #Advisory https://github.com/advisories/GHSA-2r68-g678-7qr3

    Post summary

    The advisory discloses an OAuth scope enforcement flaw in MCP’s memory service that allows read‑only clients to write or delete memories via the /mcp JSON‑RPC interface.

    00032289
    3.3K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call (#CVE-2026-49291) (High) -DC-Jun2026-695 https://dailycve.com/mcp-memory-service-oauth-read-only-clients-can-write-and-delete-memories-through-mcp-tools-call-cve-2026-49291-high-dc-jun2026-695/

    Post summary

    The post announces a new CVE (CVE‑2026‑49291) where read‑only OAuth clients in MCP Memory Service can write or delete memories via MCP tools, highlighting a serious authorization flaw.

    0001038
    216 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49291 mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope… https://www.cve.org/CVERecord?id=CVE-2026-49291 ----- Traducción: CVE-2026-49291 mcp… http://infoflow.cloud`

    Post summary

    CVE‑2026‑49291 reveals a privilege‑checking weakness in the mcp‑memory‑service’s `/mcp` JSON‑RPC endpoint that is fixed in version 10.65.3, with no PoC or exploitation evidence reported.

    0000026
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-49291 mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope… https://www.cve.org/CVERecord?id=CVE-2026-49291

    Post summary

    The CVE‑2026‑49291 vulnerability in mcp‑memory‑service allows potential unauthorized access because the `/mcp` endpoint accepts only OAuth `read` scope before version 10.65.3.

    00000244
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-49291 Insufficient OAuth Scope Validation in mcp-memory-service HTTP MC... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49291 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces CVE‑2026‑49291, describing an insufficient OAuth scope validation flaw in mcp‑memory‑service HTTP MC, with links to vulnerability details and alert setup, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000051
    4.1K followersView on X

Explore more