Executive brief
Fast Note Sync Service is an open-source synchronization platform for note management and REST API access. A critical vulnerability chain allows unauthenticated attackers to register accounts, bypass administrator checks, obtain JWT signing keys from a configuration endpoint, and forge authentication tokens to impersonate any user including administrators. Successful exploitation results in complete account takeover, unauthorized access to all user notes and metadata, and ability to modify or delete synchronized content.
Technical details
This vulnerability chain combines multiple weaknesses: (1) an authentication bypass through an incorrect administrator authorization check when admin-uid is set to 0, allowing any authenticated user to pass privilege checks; (2) exposure of authTokenKey (JWT signing material) via an unprotected administrative configuration endpoint; (3) weak JWT token construction using authTokenKey concatenated with machine_id, which may be empty, known, or predictable in Docker deployments; and (4) uncontrolled user self-registration. An unauthenticated attacker can self-register a normal account, access the admin configuration endpoint due to the flawed authorization check, extract authTokenKey, and forge valid JWTs for arbitrary user identifiers. No patches have been confirmed by the maintainer.
Affected products
- fast-note-sync-service <=2.13.7
Timeline
- 2026-05-07: disclosed: Vulnerability reported on GitHub issue #268
- 2026-09-01: advisory: CVE-2026-52111 assigned and published