PT-2026-82734 · Trilium · Trilium

·

CVE-2026-77438

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trilium versions prior to 0.104.0
Description The public share-search endpoint does not enforce shareCredentials and shareHiddenFromTree controls. The endpoint authorizes only the ancestor note provided in the request and performs a full-text search across the published subtree, returning the title, share identifier, and hierarchical path of matching notes without verifying if the individual note requires a password or is hidden. An unauthenticated visitor can use this endpoint as a boolean oracle—a system that provides a yes/no answer to a query—to confirm arbitrary substrings and recover the full content of protected shared notes.
Recommendations Update to version 0.104.0.

Exploit

Fix

Information Disclosure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77438
GHSA-6RXV-6W3Q-7MV9

Affected Products

Trilium