PT-2025-18288 · Joplin · Joplin

Zonia3000

·

Published

2025-04-30

·

Updated

2025-06-15

·

CVE-2025-27134

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joplin versions prior to 3.3.3
Description The issue concerns a privilege escalation vulnerability in the Joplin server. This vulnerability allows non-admin users to exploit the API endpoint PATCH /api/users/:id to set the is admin field to 1, enabling them to perform administrative actions without proper authorization.
Recommendations For versions prior to 3.3.3, update to version 3.3.3 to resolve the issue. As a temporary workaround, consider restricting access to the PATCH /api/users/:id API endpoint to prevent exploitation. Additionally, restrict the ability to set the is admin field to authorized personnel only.

Exploit

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27134
GHSA-XJ67-649M-3P8X

Affected Products

Joplin