Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure. | |
| Title | Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change | |
| First Time appeared |
Usememos
Usememos memos |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T18:05:05.563Z
Reserved: 2026-09-01T11:03:27.973Z
Link: CVE-2026-84203
No data.
Status : Received
Published: 2026-09-01T16:17:34.600
Modified: 2026-09-01T19:17:30.383
Link: CVE-2026-84203
No data.
OpenCVE Enrichment
No data.
Weaknesses