Unknown · Open-Wearables · CVE-2026-78154
**Name of the Vulnerable Software and Affected Versions**
the-momentum open-wearables versions prior to 0.6.3
**Description**
An issue exists in the Public Invitation-Code Redemption Endpoint where the `redeem invitation code()` function in the `backend/app/api/routes/v1/user invitation code.py` file fails to properly authenticate requests. By manipulating the `code` argument, a remote attacker can bypass authentication requirements.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `redeem invitation code()` function to minimize the risk of exploitation.