LiveActive security incident?Get immediate response
CVE Record

CVE-2026-51584: An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials br...

An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A remote attacker may be able to take over accounts on usememos v0.27.1 when the affected SSO sign-in flow is used. The application trusts an identifier the attacker can influence instead of securely tying the login to the identity provider’s stable user identity. Successful abuse could expose or alter sensitive data and administrative settings.

Executive priority

Treat exposed usememos v0.27.1 deployments using SSO as an urgent remediation priority. Rapidly inventory affected systems, reduce external reachability, monitor for account compromise, and follow vendor guidance. Evidence of exploitation is currently incomplete, but the potential impact and low attack complexity justify immediate attention.

Technical view

The ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go reportedly matches SSO identities using an attacker-controllable identifier without binding it to the IdP’s stable subject claim. This is classified as CWE-287 and scored CVSS 3.1 9.8: network-accessible, low complexity, unauthenticated, and requiring no user interaction.

Likely exposure

Likely exposure is limited to usememos v0.27.1 instances using or exposing the affected SSO sign-in flow. The supplied sources do not establish whether SSO is enabled by default, whether other versions are affected, or how many internet-accessible deployments exist.

Exploitation context

The CVE is not listed as KEV in the supplied bundle. The provided evidence does not establish active exploitation or characterize exploit maturity. Nevertheless, unauthenticated remote account takeover with low attack complexity creates substantial risk wherever the affected SSO flow is reachable.

Researcher notes

The core trust failure is identifier-based SSO account matching without stable-subject binding. The bundle identifies one version and code path but provides no confirmed fixed version, patch commit, default configuration, affected-version range, or forensic indicators. Avoid broadening product or version scope without further vendor evidence.

Mitigation direction

  • Identify usememos v0.27.1 deployments and determine whether the affected SSO flow is enabled.
  • Check official usememos guidance for a corrected release or supported remediation.
  • Until guidance is available, consider restricting or temporarily disabling affected SSO access after operational review.
  • Protect sensitive instances with network access controls and monitor authentication activity.

Validation and detection

  • Confirm the deployed usememos version from trusted inventory or application metadata.
  • Verify whether SSO is configured and whether its sign-in endpoint is externally reachable.
  • Review authentication logs for unexpected SSO identity mappings, account changes, or privileged sessions.
  • After remediation, verify SSO accounts bind to the identity provider’s stable subject claim.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-287: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-51584 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-51584Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-287 · source CWE mapping

Improper Authentication

Improper Authentication represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.