CVE-2026-105786
Deferred Deferred - Pending Action

Joplin Note-Taking App Session Hijacking via Application Authorization

Vulnerability report for CVE-2026-105786, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic consent page, and the public packages/server/src/routes/api/application_auth.ts endpoint passes it to ApplicationModel.createAppPassword without authenticating or binding the redeemer. An attacker can cause a victim to approve the attacker's identifier, redeem a durable application ID and password, and exchange the credential for a victim session with full read and write access to synchronized data. This vulnerability is fixed in 3.7.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
laurent22 joplin < 3.7.13

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105786 is a vulnerability in Joplin Server versions 3.7.1 and earlier. It allows an attacker to trick a logged-in user into approving an arbitrary application authorization identifier through a generic consent page. The attacker then redeems this identifier without authentication to obtain persistent credentials for the victim's account, gaining full read and write access to synchronized data.

Detection Guidance

Check Joplin server version with: curl -s https://your-joplin-server/version | grep version. If version is 3.7.1 or earlier, the system is vulnerable. Review server logs for unauthorized application authorization attempts or unexpected POST requests to /applications/:id/confirm without valid sessions or CSRF tokens.

Impact Analysis

An attacker can gain full access to your Joplin account, including all notes, notebooks, and attachments. They can read, modify, or delete your data and even publish content publicly. The credentials remain valid until manually revoked by you.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. It may result in data breaches, non-compliance with privacy regulations, and potential legal consequences due to unauthorized data exposure.

Mitigation Strategies

Upgrade Joplin server to version 3.7.13 or later immediately. Ensure all instances are updated to prevent exploitation. Review and revoke any unauthorized application passwords in user settings. Monitor for suspicious activity or unauthorized access to accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105786. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart