Improper access control in Joplin Server - CVE-2026-34600
Published: May 26, 2026
Joplin Server
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the delta API and ChangeModel.delta when synchronizing shared items. A remote user can trigger synchronization after access to a shared note has been removed to disclose sensitive information.
Only instances with DELTA_INCLUDES_ITEMS enabled are vulnerable. User interaction is required to perform synchronization.