๐Ÿ” CVE Alert

CVE-2026-46649

UNKNOWN 0.0

Joplin: SSO Auth Code Login Missing Rate Limiting โ€” 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.

CWE CWE-307
Vendor laurent22
Product joplin
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for laurent22 joplin

Be the first to know when new unknown vulnerabilities affecting laurent22 joplin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

laurent22 / joplin
< 3.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h github.com: https://github.com/laurent22/joplin/pull/15433 github.com: https://github.com/laurent22/joplin/commit/fd8c1fb53f98f689e846dc164e39f307f09b684d github.com: https://github.com/laurent22/joplin/tree/v3.7.2