SAML Authentication Flaw in Joplin Server Affects User Account Security
CVE-2026-55210

7.4HIGH

Key Information:

Vendor

Laurent22

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-55210?

The Joplin Server's SAML authentication feature is vulnerable due to improper validation of user accounts. Specifically, before version 3.7.2, the UserModel.ssoLogin() method allowed attackers to gain unauthorized access to user accounts by exploiting an IdP-asserted email match. When mixed local and SAML authentication is used, an attacker could leverage their IdP session to impersonate a local user without needing their password, thereby accessing and potentially modifying sensitive information such as notes and settings. This vulnerability underscores the importance of robust account validation and is addressed in the latest release.

Affected Version(s)

joplin < 3.7.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.