Unauthenticated Password Bypass in Note Mark Application
CVE-2026-41571

9.4CRITICAL

Key Information:

Vendor

Enchant97

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-41571?

In version 0.19.2 of the Note Mark application, a critical flaw exists in the password matching function, IsPasswordMatch, located in the backend database model. This vulnerability allows OIDC-registered users, created with an empty password, to exploit the application by submitting a hard-coded bcrypt placeholder, resulting in an unauthenticated login bypass. This security issue enables unauthorized access to user accounts without any interaction or authentication required. The vulnerability has been addressed in version 0.19.3.

Affected Version(s)

note-mark = 0.19.2

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.