CVE-2026-84203 HIGH

CVE-2026-84203: Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change

Vendor Usememos
Product memos
Weakness CWE-613 · Insufficient session expiration
Published September 1, 2026
Last update September 1, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.

Key dates

02Disclosure timeline

September 1, 2026 CVE published