PT-2026-96274 · Unknown · Joplin Server

CVE-2026-46649

·

Published

2026-09-21

·

Updated

2026-09-28

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joplin Server versions prior to 3.7.2
Description The GET '/api/login with code/:id' endpoint fails to apply the limiterLoginBruteForce mechanism when processing nine-digit SSO authentication codes. This allows an unauthenticated attacker to perform unlimited guesses for a code during an active SSO login session. A successful guess provides a full session token, granting unauthorized access to and modification of the user's notes, notebooks, and account settings.
Recommendations Update to version 3.7.2.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46649
GHSA-6VWC-4HRG-QP5H

Affected Products

Joplin Server