Description
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read enabling remote exploitation
Action: Patch
AI Analysis

Impact

The vulnerability arises from an out-of-bounds read in the try_read_command_asciiauth function within memcached's mcmc Tokenizer logic. An attacker can craft a malformed authentication request that causes the server to read memory beyond intended bounds, potentially exposing sensitive data or causing a denial of service. This weakness can compromise confidentiality and availability and is identified as an out-of-bounds read flaw.

Affected Systems

Memcached versions 1.6.41, 1.6.42, and 1.6.43 are affected. The fix is incorporated in version 1.6.44 and later. Systems running these vulnerable releases, particularly those exposed to external networks, are at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in CISA's KEV catalog. Remote attackers can trigger the flaw by sending specific authentication packets, making the threat vector remote. Even though exploitation probability is low, the impact of a successful read could be significant.

Generated by OpenCVE AI on September 15, 2026 at 14:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade memcached to version 1.6.44 or later to apply the patch.
  • If an upgrade is delayed, disable ASCII authentication or configure the server to reject malformed authentication requests.
  • Restrict access to the memcached port through firewall rules or network segmentation to limit exposure to trusted hosts.
  • Monitor for anomalous authentication traffic and audit logs for signs of exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
Title memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds
First Time appeared Memcached
Memcached memcached
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*
Vendors & Products Memcached
Memcached memcached
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Memcached Memcached
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T15:55:39.158Z

Reserved: 2026-09-13T05:23:49.531Z

Link: CVE-2026-90698

cve-icon Vulnrichment

Updated: 2026-09-15T15:55:31.139Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T09:17:02.300

Modified: 2026-09-15T16:17:40.657

Link: CVE-2026-90698

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T08:30:12Z

Links: CVE-2026-90698 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read