
CVE-2026-40263 Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied use… https://www.cve.org/CVERecord?id=CVE-2026-40263
Post summary
The note announces a vulnerability in Note Mark 0.19.1 and earlier, where the login endpoint’s bcrypt verification is conditional, explaining how the issue can be exploited.

