Authorization Flaw in Joplin Note-Taking Application
CVE-2026-105786
What is CVE-2026-105786?
Joplin, an open-source note-taking and to-do application, has a vulnerability that allows attackers to exploit an authorization flaw in earlier versions than 3.7.13. The issue arises because ApplicationModel.ts accepts an application authorization identifier chosen by the caller. Through a generic consent page, this identifier can be bound to a logged-in user. The public API endpoint application_auth.ts does not authenticate the identifier before passing it to createAppPassword. As a result, a malicious actor can trick a victim into approving their identifier, allowing them to obtain a valid application ID and password. This grants full access to the victim's data, including read and write permissions. Users are advised to update to version 3.7.13 or later to mitigate this risk.
Affected Version(s)
joplin < 3.7.13
