Username Enumeration Vulnerability in Note Mark Application by Enchant97
CVE-2026-40263
3.7LOW
What is CVE-2026-40263?
The Note Mark application, a popular open-source note-taking tool, contains a vulnerability where the login endpoint verifies bcrypt passwords based only on the existence of a supplied username. This behavior allows attackers to determine valid usernames by measuring the response time of the verification process. By exploiting this timing variation, unauthorized users can perform targeted credential attacks, leading to potential compromise of user accounts. A patch has been released in version 0.19.2 to mitigate this risk.
Affected Version(s)
note-mark < 0.19.2
