Junglewise Threat Intelligence

CVE-2026-55179: Joplin Server authorization bypass in GET /items/:id/content

CVE-2026-55179 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Executive brief

Joplin Server is an open source collaboration platform for note-taking and task management. Prior to version 3.7.2, any authenticated user could read other users' notes and items by guessing or obtaining their internal IDs, bypassing access controls and potentially exposing sensitive information unless end-to-end encryption was enabled.

Technical details

The GET /items/:id/content route in packages/server/src/routes/index/items.ts fails to validate that the authenticated user owns or has access to the requested item before returning its content. An attacker with valid authentication can enumerate or guess item IDs belonging to other users and retrieve their unencrypted content. The vulnerability is fixed in version 3.7.2 with improved validation logic.

Affected products

  • Laurent22 Joplin Server before 3.7.2

Timeline

  • 2026-09-21: disclosed
  • 2026-06-12: patched: Fix merged in PR #15657

References