OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-46649

CRITICAL · CVSS 9.1 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Joplin Server's GET /api/login_with_code/:id endpoint is vulnerable to brute-force attacks due to the lack of a login attempt limiter, allowing unauthenticated attackers to guess a nine-digit SSO authentication code without restriction. Successful exploitation grants full access to a user's notes, notebooks, and account settings, posing a significant risk to user data integrity and confidentiality. Organizations using Joplin Server versions prior to 3.7.2 should prioritize upgrading to mitigate this critical vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46649
Severity
CRITICAL
CVSS
9.1
EPSS
0.50%

Original NVD Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.