CVE-2026-78154General

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The endpoint is public on purpose and the invitation code is the credential. This is the standalone SDK onboarding path for mobile apps that have no backend of their own: a developer generates a code via the authenticated dashboard endpoint, the user types it into the app, and it's redeemed for SDK-scoped tokens.

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-23); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-23: 2Mentions · 2026-08-24: 1Technical Details · 2026-08-23: 108-2308-24
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-232
Disclosure1General1
2026-08-241
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-78154 Missing Authentication in the-momentum open-wearables Public Invitation-Code Redemption Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78154

    Post summary

    The entry simply lists CVE-2026-78154 as a missing authentication issue with a link to more information, but provides no further detail.

    00010122
    4.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-78154 A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user… https://www.cve.org/CVERecord?id=CVE-2026-78154

    Post summary

    The post cites CVE-2026-78154 and points to the official CVE entry but provides no PoC, exploit, active use, patch, or detailed technical information.

    00010987
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-78154 A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user… https://www.cve.org/CVERecord?id=CVE-2026-78154 ----- Traducción: CVE-2026-78154 Se … http://infoflow.cloud`

    Post summary

    CVE‑2026‑78154 is a newly disclosed vulnerability in the‑momentum open‑wearables that affects the redeem_invitation_code function; no exploitation or patch details are provided.

    0000036
    102 followersView on X

Explore more