CVE-2026-84203

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token indefinitely, bypassing the password change security measure.

  • Published Sep 1, 2026
  • CVSS 8.6 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84203 at the National Vulnerability Database