CVE-2026-52111
—Privilege escalation via authTokenKey exposure in fast-note-sync-service
fast-note-sync-service versions 2.13.7 and earlier expose the authTokenKey through the admin configuration endpoint (CWE-284, improper access control). Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), a remote attacker can reach this endpoint over the network without prior privileges or user interaction, retrieve the exposed authTokenKey, and use it to escalate privileges to administrative level, with potentially full impact on confidentiality, integrity, and availability. Any deployment running fast-note-sync-service 2.13.7 or earlier is affected. There is currently no known public proof-of-concept, no listing in CISA KEV, and a low EPSS score of 0.3%, indicating no confirmed exploitation at this time.
What to do: Upgrade fast-note-sync-service to a release newer than 2.13.7 as soon as a patched version is available. Until then, restrict network access to the admin configuration endpoint (e.g., via firewall rules, VPN, or an authenticated reverse proxy), rotate the authTokenKey and any tokens derived from it, and review logs for unauthenticated access to the admin configuration endpoint.
| fast-note-sync-service | <= 2.13.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.