CVE-2026-41571Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: "null" to the internal login endpoint receives a valid session for that user. The bypass is unauthenticated and requires no user interaction. This issue has been patched in version 0.19.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-12); latest day: 3
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01223Mentions · 2026-05-04: 2Mentions · 2026-05-12: 3Mentions · 2026-05-23: 3Technical Details · 2026-05-04: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-23: 305-0405-1205-23
Signal classification2 categories
Disclosure
675.0%
General
225.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure2
2026-05-123
Disclosure1General2
2026-05-233
Disclosure3
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Researchers from http://aisafe.io disclosed CVE-2026-41571 on April 25, 2026 (GitHub Advisory published). The flaw allows any unauthenticated attacker to spawn a valid session as any OIDC-only user by submitting the literal string "null" as the password. Once inside, the attacker…

    Post summary

    Researchers announced CVE-2026-41571, a vulnerability that allows unauthenticated session creation for any OIDC-only user by submitting the password "null".

    1000046
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources GitHub Advisory Database: CVE-2026-41571 Details: Note Mark Repository: DailyCVE Analysis:… TL;DR Any OIDC-registered user on Note Mark (v0.19.2 and earlier) can be hijacked with a single HTTP request: POST /api/auth/token with username and password: "null".

    Post summary

    The post announces a new CVE (CVE-2026-41571) targeting Note Mark, describing the vulnerability mechanism of hijacking OIDC users with a single token request.

    1000044
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Note Mark OIDC Auth Bypass: Login With Password "null" (CVSS 9.4, CVE-2026-41571). TL;DR Any OIDC-registered user on Note Mark (v0.19.2 and earlier) can be hijacked with a single HTTP request: POST /api/auth/token with username and password: "null".

    Post summary

    The note reveals a high‑severity OIDC authentication bypass (CVE‑2026‑41571) in Note Mark, allowing an attacker to hijack any registered user via a simple HTTP request using a null password.

    1000048
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.4 CRITICAL · CVE-2026-41571 · 9.4 → 0.19.2 CVE: CVE-2026-41571 CVSS: 9.4 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a CVE-2026-41571 with CVSS 9.4 severity but provides no PoC, exploit details, or patch information; it functions as a high‑severity disclosure.

    1000034
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-41571 CVSS: 9.4 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Severity: CRITICAL Status: Critical advisory Note Mark is an open-source note-taking application.

    Post summary

    A brief critical advisory alerts that CVE-2026‑41571 affects the open‑source app Note Mark, providing a CVSS score and severity but no PoC, exploit code, active exploitation evidence, or remediation details.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41571-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to research about CVE-2026-41571, but no concrete evidence of PoC, exploit, active use, patch, technical details, or false positive is provided.

    0000014
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41571 Unauthenticated Authentication Bypass in Note Mark 0.19.2 via Hard-Coded Password Placeholder https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41571

    Post summary

    This brief notice announces an unauthenticated authentication bypass vulnerability (CVE‑2026‑41571) in Note Mark 0.19.2 that stems from a hard‑coded password placeholder; no PoC, exploit, active exploitation, or patch information is provided.

    0000033
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41571 Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder … https://www.cve.org/CVERecord?id=CVE-2026-41571

    Post summary

    The Note Mark application’s IsPasswordMatch function falls back to a hard‑coded bcrypt("null") placeholder, potentially undermining password authentication. No PoC, exploit, or patch details are supplied.

    0000087
    57.4K followersView on X

Explore more