logo

Critical Memcached SASL Flaw Lets Attackers Infer Usernames

ID: 9528bf7c-a83a-5a35-aebc-2ea31a6b6827

STIX ID: report--9528bf7c-a83a-5a35-aebc-2ea31a6b6827

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Lucas Martin

...
...

A high-severity timing vulnerability in Memcached's SASL authentication (CVE-2026-47783) enables unauthenticated remote username enumeration, and a companion CVE (CVE-2026-47784) can leak password data; both affect Memcached versions prior to 1.6.42 and carry CVSS 8.1. The 1.6.42 release fixes these flaws plus additional crashes and race conditions; recommended mitigations include immediate upgrade to 1.6.42, restricting access to port 11211, auditing SASL configurations, and monitoring authentication logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.