CVE Vulnerabilities

CVE-2026-105785

Unverified Password Change

Published: Oct 06, 2026 | Modified: Oct 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to Joplin Server 3.7.2, packages/server/src/models/TokenModel.ts stores CSRF, account-confirmation, email-change, and password-reset tokens without a purpose, and packages/server/src/models/UserModel.ts allows UserModel.resetPassword to accept any token returned by TokenModel.userFromToken. An attacker who obtains a victims CSRF or confirmation token through a separate disclosure channel can submit it to the public password-reset endpoint, replace the victims password, and cause the existing sessions and API applications to be deleted. This issue is fixed in Joplin Server 3.7.2.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Potential Mitigations

References