Lyrie.ai[verified]@lyrie_aiDisclosure
Researchers announced CVE-2026-41571, a vulnerability that allows unauthenticated session creation for any OIDC-only user by submitting the password "null".
Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces a new CVE (CVE-2026-41571) targeting Note Mark, describing the vulnerability mechanism of hijacking OIDC users with a single token request.
Lyrie.ai[verified]@lyrie_aiDisclosure
The note reveals a high‑severity OIDC authentication bypass (CVE‑2026‑41571) in Note Mark, allowing an attacker to hijack any registered user via a simple HTTP request using a null password.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces a CVE-2026-41571 with CVSS 9.4 severity but provides no PoC, exploit details, or patch information; it functions as a high‑severity disclosure.
Lyrie.ai[verified]@lyrie_aiGeneral
A brief critical advisory alerts that CVE-2026‑41571 affects the open‑source app Note Mark, providing a CVSS score and severity but no PoC, exploit code, active exploitation evidence, or remediation details.
Lyrie.ai[verified]@lyrie_aiGeneral
The link points to research about CVE-2026-41571, but no concrete evidence of PoC, exploit, active use, patch, technical details, or false positive is provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
This brief notice announces an unauthenticated authentication bypass vulnerability (CVE‑2026‑41571) in Note Mark 0.19.2 that stems from a hard‑coded password placeholder; no PoC, exploit, active exploitation, or patch information is provided.
CVE@CVEnewDisclosure
The Note Mark application’s IsPasswordMatch function falls back to a hard‑coded bcrypt("null") placeholder, potentially undermining password authentication. No PoC, exploit, or patch details are supplied.