CVE-2026-51584: An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials br...
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.
Security readout for executives and security teams
Plain-English summary
A remote attacker may be able to take over accounts on usememos v0.27.1 when the affected SSO sign-in flow is used. The application trusts an identifier the attacker can influence instead of securely tying the login to the identity provider’s stable user identity. Successful abuse could expose or alter sensitive data and administrative settings.
Executive priority
Treat exposed usememos v0.27.1 deployments using SSO as an urgent remediation priority. Rapidly inventory affected systems, reduce external reachability, monitor for account compromise, and follow vendor guidance. Evidence of exploitation is currently incomplete, but the potential impact and low attack complexity justify immediate attention.
Technical view
The ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go reportedly matches SSO identities using an attacker-controllable identifier without binding it to the IdP’s stable subject claim. This is classified as CWE-287 and scored CVSS 3.1 9.8: network-accessible, low complexity, unauthenticated, and requiring no user interaction.
Likely exposure
Likely exposure is limited to usememos v0.27.1 instances using or exposing the affected SSO sign-in flow. The supplied sources do not establish whether SSO is enabled by default, whether other versions are affected, or how many internet-accessible deployments exist.
Exploitation context
The CVE is not listed as KEV in the supplied bundle. The provided evidence does not establish active exploitation or characterize exploit maturity. Nevertheless, unauthenticated remote account takeover with low attack complexity creates substantial risk wherever the affected SSO flow is reachable.
Researcher notes
The core trust failure is identifier-based SSO account matching without stable-subject binding. The bundle identifies one version and code path but provides no confirmed fixed version, patch commit, default configuration, affected-version range, or forensic indicators. Avoid broadening product or version scope without further vendor evidence.
Mitigation direction
Identify usememos v0.27.1 deployments and determine whether the affected SSO flow is enabled.
Check official usememos guidance for a corrected release or supported remediation.
Until guidance is available, consider restricting or temporarily disabling affected SSO access after operational review.
Protect sensitive instances with network access controls and monitor authentication activity.
Validation and detection
Confirm the deployed usememos version from trusted inventory or application metadata.
Verify whether SSO is configured and whether its sign-in endpoint is externally reachable.
Review authentication logs for unexpected SSO identity mappings, account changes, or privileged sessions.
After remediation, verify SSO accounts bind to the identity provider’s stable subject claim.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-287: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-287 · source CWE mapping
Improper Authentication
Improper Authentication represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.