CVE-2026-84203
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.
- Published Sep 1, 2026
- CVSS 8.6 high
- 0.4% chance of exploitation in the next 30 days (EPSS)