Executive brief
Joplin Server is a note-taking application that stores and organizes user notes, files, and settings. In deployments using both SAML and local password authentication, an attacker can log in to a victim's local account using SAML if they control a SAML identity provider (IdP) that can assert the victim's email address. This allows unauthorized access to or modification of the victim's notes, files, and account settings without knowing their password.
Technical details
The vulnerability exists in Joplin Server's UserModel.ssoLogin() function, which does not validate the is_external flag when matching accounts by IdP-asserted email. An attacker with control of an IdP session can POST to /api/saml with an email matching an existing local password account, receive a valid session, and access the victim's account. The fix restricts SAML login to accounts explicitly created via SSO, rejecting SAML logins for local password accounts.
Affected products
- Joplin Server before 3.7.2
Timeline
- 2026-09-21: disclosed: CVE-2026-55210 published
- 2026-06-11: patched: Fix merged to dev branch in commit b6d69d0