CVE-2026-47783Disclosure(memcached / memcached)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch memcached memcached systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • memcached

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-26); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
memcached

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-05-26: 4Mentions · 2026-05-27: 2Mentions · 2026-05-30: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-26: 4Technical Details · 2026-05-27: 2Technical Details · 2026-05-30: 1Technical Details · 2026-06-02: 105-2605-2705-3006-02
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-264
Disclosure3Patch1
2026-05-272
Disclosure2
2026-05-301
Patch1
2026-06-021
Disclosure1
Full discourse8 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-47783 & CVE-2026-47784: Two SASL vulnerabilities in Memcached, 8.1 rating 🔥 Two new vulnerabilities Memcached allow an attacker to enumerate valid usernames on the system and guess their passwords because password and username data for SASL password database authentication has a timing side channel. 👉 https://nt.ls/zZBd0

    Post summary

    Two new Memcached SASL vulnerabilities (CVE‑2026‑47783 & CVE‑2026‑47784) expose a timing side‑channel that allows attackers to enumerate valid usernames and guess passwords, rated at a CVSS score of 8.1.

    1501061.1K
    7.6K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad crítica de Memcached SASL permite inferir usuarios válidos Se ha revelado una vulnerabilidad de seguridad en Memcached (identificada como CVE-2026-47783 ) https://blog.elhacker.net/2026/05/vulnerabilidad-critica-de-memcached.html

    Post summary

    An article announces that CVE‑2026‑47783 is a critical Memcached SASL vulnerability permitting attackers to infer valid usernames; no evidence of a PoC, exploit code, patch, or active attacks is provided.

    040921.7K
    140.9K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Memcachedに認証情報を推測可能にする高危険度脆弱性2件が見つかった。SASL認証処理の応答時間差を悪用し、ユーザー名やパスワードを段階的に特定される恐れがある。 問題はCVE-2026-47783とCVE-2026-47784で、いずれもCVSS 8.1。1.6.42未満のMemcachedが影響を受ける。1件目は有効ユーザー名発見時に処理を早期終了することで応答時間差が発生し、攻撃者が有効アカウントを列挙可能となる。 2件目ではパスワード比較に通常のmemcmp処理を使用していたため、1文字ごとの差異が処理時間へ反映される。攻撃者はこの差を分析し、パスワードを1バイトずつ推測できる可能性がある。 開発チームはMemcached 1.6.42で両問題を修正したほか、バイナリプロトコルの整数オーバーフローや認証リロード時のデータ競合、巨大トークンによるクラッシュなど複数の不具合も修正した。運用環境では速やかな更新適用が推奨されている。 https://securityonline.info/memcached-sasl-vulnerability-cve-2026-47783/

    Post summary

    Two high‑severity Memcached SASL timing‑attack vulnerabilities (CVE‑2026‑47783/84) were disclosed; they allow credential enumeration by measuring response latency, and both are fixed in Memcached 1.6.42 with an update recommendation.

    0101032.6K
    14.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Memcached SASLに深刻な脆弱性。CVE-2026-47783は応答時間でのサイドチャネル攻撃によるユーザ名列挙。CVE-2026-47784は同様のパスワード推測。バージョン1.6.42で修正。 https://securityonline.info/memcached-sasl-vulnerability-cve-2026-47783/

    Post summary

    The post discloses Memcached SASL side‑channel vulnerability CVE‑2026‑47783/84 and confirms that version 1.6.42 includes a patch.

    010511.3K
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Memcached before 1.6.42 got 2 CVEs https://www.openwall.com/lists/oss-security/2026/05/24/7 CVE-2026-47783 / CVE-2026-47784 for timing side channels in processing of username / password data for SASL password database authentication

    Post summary

    Memcached versions prior to 1.6.42 are affected by CVE-2026-47783 and CVE-2026-47784, which involve timing side channels during SASL username/password authentication.

    00010216
    4.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Memcached の脆弱性 CVE-2026-47783 が FIX:SASL 欠陥による有効なユーザー名の推測 https://iototsecnews.jp/2026/05/26/critical-memcached-sasl-vulnerability-let-attackers-infer-valid-usernames/ 今回の Memcached の脆弱性 CVE-2026-47783 は、認証処理で生じる僅かな時間の差に起因します。システムが正しいユーザー名を受け取った時と、そうではない時で、内部の計算手順に微妙な違いが生じていたことが問題の核心です。この処理時間のバラつきを攻撃者が精密に測定することで、有効なアカウント名だけを効率よく特定できてしまう性質を持っています。パスワードが盗まれなくても、ログインの入り口が判明することは、その後の不正アクセスを助長する大きなリスクに繋がります。ご利用のチームは、ご注意ください。 #CVE202647783 #Memcached #Vulnerability

    Post summary

    The article reveals a timing‑based SASL authentication flaw in Memcached (CVE‑2026‑47783) that allows attackers to infer valid usernames, but no PoC, exploit, or patch details are provided.

    0000058
    491 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-47783 (CVSS 8.1) memcached <1.6.42 has timing side channel in SASL auth allowing username enumeration. Impact: Remote attackers may exploit timing differences to discover valid usernames. Patch to 1.6.42+ immediately. #CVE #Vulnerability #PatchNow https://t.co/mWx3QUJJyV

    Post summary

    CVE-2026-47783 is a timing side‑channel flaw in memcached 1.6.42‑under‑, enabling username enumeration via SASL authentication; patching to 1.6.42+ resolves the issue.

    0000068
    32 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Memcached is leaking your usernames. And then your passwords. CVE-2026-47783 & CVE-2026-47784 - two SASL vulns (CVSS 8.1) that let attackers enumerate valid usernames then brute-force credentials from the exposed SASL password database. 8,539 vulnerable instances confirmed globally. US leads with 1,532. http://vulntracker.io

    Post summary

    The article announces two Memcached SASL vulnerabilities (CVE-2026-47783 and CVE-2026-47784) that allow attackers to enumerate usernames and brute‑force credentials, with 8,539 affected instances worldwide.

    0000097
    655 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmemcachedmemcached---

Explore more