PT-2026-96274 · Unknown · Joplin Server
CVE-2026-46649
·
Published
2026-09-21
·
Updated
2026-09-28
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Joplin Server versions prior to 3.7.2
Description
The GET '/api/login with code/:id' endpoint fails to apply the
limiterLoginBruteForce mechanism when processing nine-digit SSO authentication codes. This allows an unauthenticated attacker to perform unlimited guesses for a code during an active SSO login session. A successful guess provides a full session token, granting unauthorized access to and modification of the user's notes, notebooks, and account settings.Recommendations
Update to version 3.7.2.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joplin Server