CVE-2026-84203: Usememos Memos
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
Affected products
- Usememos Memos: from 0.26.0, up to and including 0.30.0
Published 2026-09-01. Last modified 2026-09-08.