CVE-2026-84203: Usememos Memos

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.

Affected products

  • Usememos Memos: from 0.26.0, up to and including 0.30.0

Published 2026-09-01. Last modified 2026-09-08.