External risk intelligence

Joplin Server Authentication Code Brute Force Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-46649

Joplin Server is a self-hosted backend service designed to synchronize notes and to-do lists across devices. It commonly acts as a web-accessible API or service endpoint to facilitate remote access and multi-device connectivity, making the login and authentication endpoints reachable from the network.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an issue in Joplin Server's authentication process that could allow an unauthenticated attacker to gain access to a user's account and data. The vulnerability lies in how the system handles authentication codes during a single sign-on process, potentially enabling unauthorized session tokens to be issued. This could lead to the modification or exposure of sensitive user notes and account settings.

  • Authentication codes can be guessed repeatedly.
  • Compromised notes affect user privacy.
  • Confirm relevance and exposure of this system.

Attack Path

How an attacker could exploit the issue

An attacker can gain access to a user's Joplin account by exploiting a weakness in the server's SSO authentication process. If an attacker can guess a valid, short-lived SSO code while a user is in the process of logging in, they can obtain a session token. This token allows them to access and change the targeted user's notes, notebooks, and account settings.

  • Unauthenticated network access required.
  • Guesses valid SSO code during active login.
  • Unauthorized access to user data and settings.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain access to a user's note-taking data. If an attacker targets a user during an active single sign-on (SSO) login attempt, they could repeatedly guess the authentication code. A correct guess would grant the attacker a session token, enabling them to access and modify the user's notes, notebooks, and account settings.

  • User's notes and account data.
  • Unlimited guesses to obtain a session token.
  • Unauthorized access and modification of notes.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Joplin Server is a self-hosted application, suggesting that infrastructure or platform teams are likely responsible for its management. The initial step involves identifying all instances of Joplin Server within the environment, determining their network exposure and business criticality, and locating the specific team or individual accountable for each instance to prioritize remediation efforts.

  • Identify Joplin Server instances and exposure.
  • Confirm business criticality and accountable owners.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Joplin Server?

Joplin Server is the self-hosted backend component for the Joplin note-taking and to-do application. It functions as a centralized service that synchronizes notes and lists across a user's various devices. Because it provides a web-accessible API for remote connectivity, it often runs as an always-on service to ensure data is available whenever a user accesses their notes.

How does the CVE-2026-46649 vulnerability work?

This vulnerability is classified as an improper restriction of excessive authentication attempts. In versions prior to 3.7.2, the SSO login endpoint fails to limit how many times a user can guess a code. This allows an attacker to repeatedly try different numbers without being blocked, potentially guessing the correct nine-digit code to hijack a session.

Can an attacker trigger this anytime against my server?

No. The flaw specifically requires an attacker to time their attempts during an active single sign-on (SSO) login process initiated by a legitimate user. It cannot be triggered by guessing codes at random times when no one is attempting to log in, as the authentication code is only valid for a ten-minute window during an ongoing session request.

Do I need to worry if my Joplin Server is internal?

Halo Surface Signal indicates that Joplin Server is typically deployed as a web-accessible service to support multi-device connectivity. If your instance is reachable from the internet, the risk is higher because remote attackers can attempt to reach the login endpoint. If it is restricted to a private, internal-only network, the window for unauthorized access is significantly reduced.

What is the first step to fix CVE-2026-46649?

The primary response is to update your Joplin Server instance to version 3.7.2 or later, which implements the necessary login rate limiting. Start by inventorying all your deployed instances to understand where they are running and who manages them. Once you have located these services, prioritize upgrading the software to close the authentication gap.

References