CVE-2026-46649EPSS p40.7%
CVE-2026-46649CVE-2026-46649
Description
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minute lifetime without applying limiterLoginBruteForce. An unauthenticated attacker who targets a user during an active SSO login can make unlimited guesses, and a correct code returns a full session token that permits access to and modification of the user's notes, notebooks, and account settings. This issue is fixed in version 3.7.2.
Scoring
| EPSS | 0.50% probability of exploitation · percentile 40.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |