{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/memos-0.26.0---0.30.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:usememos:memos:0.26.0:*:*:*:*:*:*:*","cpe:2.3:a:usememos:memos:0.30.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-84203"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Memos (0.26.0 - 0.30.0)"],"_cs_severities":["high"],"_cs_tags":["session-management","vulnerability","mssql-bypass"],"_cs_type":"advisory","_cs_vendors":["UseMemos"],"content_html":"\u003cp\u003eMemos versions 0.26.0 through 0.30.0 contain a critical session management vulnerability where the application fails to revoke existing refresh tokens upon a user password change. This security flaw means that if an attacker has already obtained a valid refresh token through previous compromise or session hijacking, they can continue to use that token to authenticate against the RefreshToken RPC endpoint. By repeatedly calling this RPC, the attacker can generate new access tokens and rotate the refresh token indefinitely, effectively bypassing the security intent of a password reset. This persistence mechanism allows an unauthorized actor to maintain account access long after the legitimate user believes they have secured their account by changing their credentials. Defenders should identify any anomalous RefreshToken RPC activity originating from sessions that predate recent password changes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to maintain persistent unauthorized access to affected Memos instances, bypassing account password changes. This impact spans all Memos deployments within the 0.26.0 to 0.30.0 range, affecting data integrity and confidentiality for all users within the environment. If compromised, attackers may gain continuous access to sensitive notes and stored information within the Memos platform without needing the current user password.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Memos instances to a version later than 0.30.0 immediately to address the session management defect identified in CVE-2026-84203.\u003c/li\u003e\n\u003cli\u003ePerform a global session revocation if suspicious activity is detected, as simple password resets will not invalidate existing sessions in affected versions.\u003c/li\u003e\n\u003cli\u003eAudit webserver access logs for anomalous, high-frequency calls to the RefreshToken RPC endpoint that may indicate automated token rotation by an unauthorized actor.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T17:07:20Z","date_published":"2026-09-01T17:07:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-memos-token-revocation/","summary":"Memos versions 0.26.0 through 0.30.0 fail to invalidate refresh tokens after a password change, enabling persistent unauthorized access via the RefreshToken RPC.","title":"Memos Refresh Token Revocation Failure","url":"https://feed.craftedsignal.io/briefs/2026-09-memos-token-revocation/"}],"language":"en","title":"CraftedSignal Threat Feed - Memos (0.26.0 - 0.30.0)","version":"https://jsonfeed.org/version/1.1"}