Account Takeover Vulnerability in Memos by UseMemos
CVE-2026-51584
9.8CRITICAL
What is CVE-2026-51584?
A vulnerability in Memos version 0.27.1 allows remote attackers to potentially take over user accounts via a flaw in the SignIn handler. The issue arises because the SSO identity linking relies solely on an attacker-controllable identifier, which is not securely bound to the identity provider's stable subject claim. This oversight permits unauthorized access, exposing user accounts to potential exploitation.
