PT-2026-84364 · Unknown · Fast-Note-Sync-Service

CVE-2026-52111

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fast-note-sync-service versions prior to 2.13.8
Description A remote attacker can escalate privileges because the admin configuration endpoint exposes the authTokenKey variable.
Recommendations Update fast-note-sync-service to version 2.13.8 or later. Restrict access to the admin configuration endpoint to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52111

Affected Products

Fast-Note-Sync-Service