Account Takeover Vulnerability in Memos by UseMemos
CVE-2026-51584

9.8CRITICAL

Key Information:

Vendor

UseMemos

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-51584?

A vulnerability in Memos version 0.27.1 allows remote attackers to potentially take over user accounts via a flaw in the SignIn handler. The issue arises because the SSO identity linking relies solely on an attacker-controllable identifier, which is not securely bound to the identity provider's stable subject claim. This oversight permits unauthorized access, exposing user accounts to potential exploitation.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.