CVE-2026-84203
Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
| CWE | CWE-613 |
| Vendor | usememos |
| Product | memos |
| Published | Sep 1, 2026 |
| Last Updated | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for usememos memos
Be the first to know when new high vulnerabilities affecting usememos memos are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
usememos / memos
0.26.0 โค 0.30.0
References
github.com: https://github.com/usememos/memos github.com: https://github.com/usememos/memos/blob/v0.30.0/server/router/api/v1/user_service.go github.com: https://github.com/usememos/memos/blob/v0.30.0/server/auth/authenticator.go vulncheck.com: https://www.vulncheck.com/advisories/memos-0.26.0-through-0.30.0-insufficient-session-expiration-on-password-change
Credits
Michael Holmquist