CVE-2026-75110: MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=
Summary
MemOS, a memory system for LLMs and AI agents, has a critical authentication bypass vulnerability when authentication is enabled but an undocumented environment variable called INTERNAL_SERVICE_SECRET is not set. An attacker can exploit this by sending requests without proper authentication headers, causing the system to incorrectly treat them as trusted internal requests and grant full administrative access, allowing them to create API keys, steal data, and gain persistent control.
Vulnerability Details
9.8(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
network
low
none
none
August 17, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75110
First tracked: August 17, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 95%