Junglewise Threat Intelligence

CVE-2026-46649: Joplin Server authentication brute force in SSO endpoint

CVE-2026-46649 · Severity: info · Published 2026-09-21

Technologies: Joplin Server. Vendors: Joplin.

Executive brief

Joplin Server is a note-taking application that stores sensitive user notes and account data. Attackers can bypass authentication on the SSO code exchange endpoint by making unlimited guesses at a nine-digit code, potentially gaining full access to a target user's notes, notebooks, and account settings without a password. This vulnerability affects versions before 3.7.2.

Technical details

The GET /api/login_with_code/:id endpoint fails to apply the limiterLoginBruteForce rate limiter, allowing unauthenticated attackers to make unlimited authentication attempts. An attacker exploiting this during an active SSO login session can guess the temporary nine-digit authentication code (valid for ten minutes) and obtain a full session token. The vulnerability requires network access and targets the SSO authentication flow, affecting all users configured with SAML authentication.

Affected products

  • Joplin Server before 3.7.2

Timeline

  • 2026-09-21: disclosed: CVE-2026-46649 published
  • 2026-05-15: patched: Fix merged in version 3.7.2 with rate limiter applied to SAML auth code endpoint

References

Related threats