Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-75110

MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
Back to all
CVE

CVE-2026-75110

MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTHENABLED=true) but the undocumented, defaultless INTERNALSERVICESECRET environment variable is unset, the isinternalrequest() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNALSERVICE_SECRET") returns None and a request omitting the X-Internal-Service header also yields None, so the comparison None == None evaluates true. The request is then treated as a trusted internal principal and granted scopes: ["all"]. As a result, an unauthenticated remote attacker can reach the admin API-key management endpoints to mint API keys for any user, enumerate keys, revoke keys, and generate a master key for persistent privileged access, as well as all data endpoints.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75110.json, https://nvd.nist.gov/vuln/detail/CVE-2026-75110, https://www.vulncheck.com/advisories/memos-authentication-bypass-via-unset-internal-service-secret, https://github.com/MemTensor/MemOS/issues/2259, https://github.com/MemTensor/MemOS, https://github.com/MemTensor/MemOS/blob/main/src/memos/api/middleware/auth.py

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00516%
EPSS Percentile
0.41683%
Introduced Version
0
Fix Available

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading