CVE-2026-34600: Joplin Server delta API returns note content after share access is revoked

Published May 19, 2026
·
Updated

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully fixed by the prior patch in #14289. In ChangeModel.delta, when DELTA_INCLUDES_ITEMS is enabled (the default), the latest state of items is attached to delta output without verifying that those items are still shared with the requesting user, and the existing removal logic only filters items deleted for all users. Additionally, the change compression logic incorrectly reduces create - delete to NOOP, which is unsafe because compression is applied per page and an item can have multiple create events; if an earlier create falls on a separate page from a later create -> delete pair, the deletion is dropped and the sequence collapses to a create. As a result, the delta API returns a create event for a deleted item with the full latest content attached, exposing notes the user no longer has access to. This issue has been fixed in version 3.5.3.

Affected Software

1 affected component
Joplin Joplin Server<=3.5.2

Event History

May 19, 2026
CVE Published
via MITRE·10:28 PM
Data Sourced
via MITRE·10:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34600?

CVE-2026-34600 is classified as a medium severity vulnerability due to the potential unauthorized access to sensitive note content.

2

How do I fix CVE-2026-34600?

To remediate CVE-2026-34600, upgrade Joplin Server to version 3.5.3 or later, which addresses the logic error in the delta API.

3

What affected versions are impacted by CVE-2026-34600?

CVE-2026-34600 affects Joplin Server versions up to and including 3.5.2.

4

What type of vulnerability is CVE-2026-34600?

CVE-2026-34600 is a logic error vulnerability that allows unauthorized users to access note content after share access has been revoked.

5

Who is affected by CVE-2026-34600?

Users of Joplin Server versions 3.5.2 and earlier are at risk of CVE-2026-34600 if they share notes and later revoke access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203