๐Ÿ” CVE Alert

CVE-2026-105786

UNKNOWN 0.0

Joplin: Unauthenticated account takeover via an attacker-chosen application-authorisation identifier

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic consent page, and the public packages/server/src/routes/api/application_auth.ts endpoint passes it to ApplicationModel.createAppPassword without authenticating or binding the redeemer. An attacker can cause a victim to approve the attacker's identifier, redeem a durable application ID and password, and exchange the credential for a victim session with full read and write access to synchronized data. This vulnerability is fixed in 3.7.13.

CWE CWE-306 CWE-330 CWE-863
Vendor laurent22
Product joplin
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for laurent22 joplin

Be the first to know when new unknown vulnerabilities affecting laurent22 joplin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

laurent22 / joplin
< 3.7.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-435m-gr6q-2fg6 github.com: https://github.com/laurent22/joplin/pull/16270 github.com: https://github.com/laurent22/joplin/commit/1a0a50afc96d4c228c736293d53de96aa23f4d00 github.com: https://github.com/laurent22/joplin/releases/tag/v3.7.13