ZeroHour

CVE-2026-52111

Privilege escalation via authTokenKey exposure in fast-note-sync-service

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

fast-note-sync-service versions 2.13.7 and earlier expose the authTokenKey through the admin configuration endpoint (CWE-284, improper access control). Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), a remote attacker can reach this endpoint over the network without prior privileges or user interaction, retrieve the exposed authTokenKey, and use it to escalate privileges to administrative level, with potentially full impact on confidentiality, integrity, and availability. Any deployment running fast-note-sync-service 2.13.7 or earlier is affected. There is currently no known public proof-of-concept, no listing in CISA KEV, and a low EPSS score of 0.3%, indicating no confirmed exploitation at this time.

What to do: Upgrade fast-note-sync-service to a release newer than 2.13.7 as soon as a patched version is available. Until then, restrict network access to the admin configuration endpoint (e.g., via firewall rules, VPN, or an authenticated reverse proxy), rotate the authTokenKey and any tokens derived from it, and review logs for unauthenticated access to the admin configuration endpoint.

Affected
fast-note-sync-service<= 2.13.7
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.