Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-52111: Fast Note Sync Service up to 2.13.7 enables admin takeover

CVE-2026-52111 · published 2 days ago
Summary

Versions of Fast Note Sync Service up to 2.13.7 reveal a secret authentication key through the admin configuration page. A remote attacker who discovers this key can pretend to be an administrator and gain full control of the service. Upgrade to a newer version or block external access to the admin page until the fix is applied.

Original advisory text
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published1 Sep 2026
Updated3 Sep 2026
First seen1 Sep 2026
Sources
CVE-2026-52111 · MITRE
Monitor software like this
Free during beta