Description
Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: "null" to the internal login endpoint receives a valid session for that user. The bypass is unauthenticated and requires no user interaction. This issue has been patched in version 0.19.3.
INFO
Published Date :
2026-05-04T17:42:32.428Z
Last Modified :
2026-05-04T20:20:53.632Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-41571 vulnerability.
| Vendors | Products |
|---|---|
| Enchant97 |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-41571.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact