Authorization Flaw in Joplin Note-Taking Application
CVE-2026-105786

8.5HIGH

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105786?

Joplin, an open-source note-taking and to-do application, has a vulnerability that allows attackers to exploit an authorization flaw in earlier versions than 3.7.13. The issue arises because ApplicationModel.ts accepts an application authorization identifier chosen by the caller. Through a generic consent page, this identifier can be bound to a logged-in user. The public API endpoint application_auth.ts does not authenticate the identifier before passing it to createAppPassword. As a result, a malicious actor can trick a victim into approving their identifier, allowing them to obtain a valid application ID and password. This grants full access to the victim's data, including read and write permissions. Users are advised to update to version 3.7.13 or later to mitigate this risk.

Affected Version(s)

joplin < 3.7.13

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.