CVE-2026-59705Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memories by accessing API routers registered without authentication middleware. Attackers can supply arbitrary user_id parameters or directly access memory retrieval endpoints to expose private memory content, or invoke pause endpoints with global_pause=true to cause denial-of-service across all users.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-07-08)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-07: 1Mentions · 2026-07-08: 3Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 307-0707-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-083
Disclosure2Patch1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-59705 — CVSS 9.8/10 ██████████ mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/OkAFL4Ep6U

    Post summary

    The tweet highlights CVE-2026-59705 as a critical, high‑CVSS vulnerability involving unauthenticated access and states that a patch is currently available.

    1000094
    64 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated API router exposure enables arbitrary memory access + global pause DoS (CVE-2026-59705) mem0’s openmemory/api component registers API routers without authentication middleware, leaving sensitive memory endpoints exposed to the internet. The root cause is missing access control/authentication enforcement (improper authorization / insecure default routing). An attacker can exploit this remotely with no credentials by supplying arbitrary user_id values or directly calling memory retrieval/write/delete endpoints, and can also invoke pause endpoints with global_pause=true to halt service. Impact includes full read/write/delete of arbitrary user memories (private data exposure and tampering) and a global denial of service affecting all users. 👉 Affected: mem0ai (openmemory/api; all versions with unauthenticated router registration) | Upgrade to No fix yet - treat as suspicious

    Post summary

    The text announces CVE-2026-59705, a critical security flaw in mem0’s openmemory/api that allows unauthenticated access to memory endpoints and a global DoS. No patch is available yet, and the issue is recommended for immediate attention.

    00000102
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59705 mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memor… https://www.cve.org/CVERecord?id=CVE-2026-59705 ----- Traducción: CVE-2026-59705 mem… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-59705, describing an unauthenticated access flaw in mem0’s openmemory/api that permits reading, writing, and deleting arbitrary user memory, and links to the official CVE record.

    0000037
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59705 mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arbitrary user memor… https://www.cve.org/CVERecord?id=CVE-2026-59705

    Post summary

    The post announces CVE-2026-59705, describing an unauthenticated access flaw in mem0's openmemory/api allowing arbitrary read, write, and delete of user memory, with no mention of PoC, exploit code, active exploitation, or mitigation.

    00000720
    57.7K followersView on X

Explore more