Unauthenticated Password Bypass in Note Mark Application
CVE-2026-41571
9.4CRITICAL
What is CVE-2026-41571?
In version 0.19.2 of the Note Mark application, a critical flaw exists in the password matching function, IsPasswordMatch, located in the backend database model. This vulnerability allows OIDC-registered users, created with an empty password, to exploit the application by submitting a hard-coded bcrypt placeholder, resulting in an unauthenticated login bypass. This security issue enables unauthorized access to user accounts without any interaction or authentication required. The vulnerability has been addressed in version 0.19.3.
Affected Version(s)
note-mark = 0.19.2
