CVE-2026-46649 Details
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.
A brute-force vulnerability has been identified in Joplin Server's SSO authentication code login endpoint, prior to version 3.7.2. The endpoint allows unlimited guesses of a nine-digit authentication code, which has a ten-minute lifetime. An unauthenticated attacker can exploit this vulnerability by targeting a user during an active SSO login, potentially gaining access to the user's notes, notebooks, and account settings.
Users can update to Joplin Server version 3.7.2 or later, where this vulnerability has been patched. For those using version 3.3.0 or earlier, it is recommended to upgrade to version 3.7.18, the latest release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/laurent22/joplin/commit/fd8c1fb53f98f689e846dc164e39f307f09b684d | [email protected] | Source CodeVendor |
| https://github.com/laurent22/joplin/pull/15433 | [email protected] | Issue TrackingVendor |
| https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h | [email protected] | AdvisoryExploitRemedyVendor |
| https://github.com/laurent22/joplin/tree/v3.7.2 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Joplin | <= 3.3.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion