CVE-2026-105786 | laurent22 Joplin up to 3.7.12 Application Authentication ApplicationModel.ts ApplicationModel.createAppPassword id improper authentication

SecurityVulns

A vulnerability was found in laurent22 Joplin up to 3.7.12. It has been declared as critical. The impacted element is the function ApplicationModel.createAppPassword of the file packages/server/src/models/ApplicationModel.ts of the component Application Authentication. Executing a manipulation of the argument ID can lead to improper authentication.

This vulnerability is registered as CVE-2026-105786. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More