CVE-2026-46649
Joplin: SSO Auth Code Login Missing Rate Limiting โ 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.
| CWE | CWE-307 |
| Vendor | laurent22 |
| Product | joplin |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for laurent22 joplin
Be the first to know when new unknown vulnerabilities affecting laurent22 joplin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
laurent22 / joplin
< 3.7.2
References
github.com: https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h github.com: https://github.com/laurent22/joplin/pull/15433 github.com: https://github.com/laurent22/joplin/commit/fd8c1fb53f98f689e846dc164e39f307f09b684d github.com: https://github.com/laurent22/joplin/tree/v3.7.2