csaf_bsi_wid_white:wid-sec-w-2026-3298
csaf_bsi_wid_white
Description
Ein Angreifer kann mehrere Schwachstellen in Joplin ausnutzen, um Benutzerkonten zu übernehmen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Daten offenzulegen oder zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuführen.
Timeline
- Published
- 2026-09-09 22:00 UTC
- Last Modified
- 2026-09-09
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
},
{
"category": "description",
"text": "Joplin ist eine quelloffene Notiz- und Aufgabenverwaltungsanwendung.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in Joplin ausnutzen, um Benutzerkonten zu übernehmen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Daten offenzulegen oder zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuführen.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Sonstiges\n- UNIX\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt für Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3298 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3298.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3298 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3298"
},
{
"category": "external",
"summary": "Joplin GitHub vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-5px3-4f5x-hjc5 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-5px3-4f5x-hjc5"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-6h4j-86j4-x4q4 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-6h4j-86j4-x4q4"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-6vwc-4hrg-qp5h vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-6vwc-4hrg-qp5h"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-8qm8-mp6h-qf35 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-8qm8-mp6h-qf35"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-9728-v7ww-mxjv vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-9728-v7ww-mxjv"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-9m2r-pv96-jxr3 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-9m2r-pv96-jxr3"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-9wp7-hr9m-3273 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-9wp7-hr9m-3273"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-f7q3-3grx-6wg9 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-f7q3-3grx-6wg9"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-jcj2-cqp2-7j53 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-jcj2-cqp2-7j53"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-mx98-7h4g-6gmh vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-mx98-7h4g-6gmh"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-qq59-gg3w-pf7v vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-qq59-gg3w-pf7v"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-r24r-gp6h-cwgf vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-r24r-gp6h-cwgf"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-r7wp-3494-fwf4 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-r7wp-3494-fwf4"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-r865-g55x-3mfc vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-r865-g55x-3mfc"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-v9jp-q5hw-w3p3 vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-v9jp-q5hw-w3p3"
},
{
"category": "external",
"summary": "GitHub Security Advisory GHSA-x9vj-jrqf-9wcm vom 2026-09-09",
"url": "https://github.com/laurent22/joplin/security/advisories/GHSA-x9vj-jrqf-9wcm"
}
],
"source_lang": "en-US",
"title": "Joplin: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-09T22:00:00.000+00:00",
"generator": {
"date": "2026-09-10T12:46:58.622+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3298",
"initial_release_date": "2026-09-09T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-09T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "<3.7.16",
"product": {
"name": "Open Source Joplin <3.7.16",
"product_id": "T059323"
}
},
{
"category": "product_version",
"name": "3.7.16",
"product": {
"name": "Open Source Joplin 3.7.16",
"product_id": "T059323-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:joplinapp:joplin:3.7.16"
}
}
}
],
"category": "product_name",
"name": "Joplin"
}
],
"category": "vendor",
"name": "Open Source"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-46649",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-46649"
},
{
"cve": "CVE-2026-46650",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-46650"
},
{
"cve": "CVE-2026-49449",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-49449"
},
{
"cve": "CVE-2026-49450",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-49450"
},
{
"cve": "CVE-2026-49453",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-49453"
},
{
"cve": "CVE-2026-55105",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-55105"
},
{
"cve": "CVE-2026-55179",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-55179"
},
{
"cve": "CVE-2026-55210",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-55210"
},
{
"cve": "CVE-2026-55456",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-55456"
},
{
"cve": "CVE-2026-59814",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-59814"
},
{
"cve": "CVE-2026-59815",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-59815"
},
{
"cve": "CVE-2026-59816",
"product_status": {
"known_affected": [
"T059323"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-59816"
}
]
}