Feed/CVE-2026-51584
CVE-2026-51584CRITICALCVSS 9.8

CVE-2026-51584

Published Aug 11, 2026·Updated Aug 12, 2026

NVD Description

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free