A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-34600

CVE-2026-34600: Joplin Information Disclosure Vulnerability

CVE-2026-34600 is an information disclosure flaw in Joplin that allows share recipients to access notes no longer shared with them due to a delta API logic error. This post covers technical details, affected versions, and fixes.

Published: May 21, 2026

CVE-2026-34600 Overview

CVE-2026-34600 is an information disclosure vulnerability in Joplin, an open source note-taking and to-do application. The flaw affects Joplin Server versions 3.5.2 and prior. A logic error in the delta API allows share recipients to download notes that are no longer shared with them. The issue is related to but not fully addressed by a prior patch in pull request #14289. The vulnerability is tracked under CWE-200: Exposure of Sensitive Information to an Unauthorized Actor.

Critical Impact

A previously authorized share recipient can retrieve the full latest content of notes after access has been revoked, exposing confidential information through the delta synchronization API.

Affected Products

  • Joplin versions 3.5.2 and prior
  • Joplin Server share recipients using the delta API
  • Fixed in Joplin version 3.5.3

Discovery Timeline

  • 2026-05-19 - CVE-2026-34600 published to NVD
  • 2026-05-20 - Last updated in NVD database

Technical Details for CVE-2026-34600

Vulnerability Analysis

The vulnerability resides in the ChangeModel.delta function of Joplin Server. When the DELTA_INCLUDES_ITEMS flag is enabled, which is the default configuration, the latest state of items is attached to the delta API output. The server does not verify that those items remain shared with the requesting user. The existing removal logic only filters items that have been deleted for all users, not items whose share permissions have been revoked for a specific recipient.

A second logic flaw exists in the change compression routine. The compression incorrectly reduces a create followed by a delete sequence to a no-op. This is unsafe because compression is applied per page of results, and an item can have multiple create events across pages.

Root Cause

The root cause is twofold. First, ChangeModel.delta lacks an authorization check ensuring the requesting user still has share access to each item attached to the delta response. Second, the page-level change compression logic drops deletion events when an earlier create event resides on a separate page from a later create-delete pair. The sequence then collapses to a create event with the full latest content attached.

Attack Vector

An authenticated user who was previously granted share access to a note can call the delta API after the share has been revoked. The API returns a create event for the revoked item containing the full latest content. Exploitation requires low privileges and some user interaction, and is delivered over the network. Refer to the GitHub Security Advisory GHSA-88x4-77rc-jw94 for additional technical context.

Detection Methods for CVE-2026-34600

Indicators of Compromise

  • Delta API requests from user accounts whose share permissions were recently revoked
  • Anomalous volumes of delta synchronization calls returning create events for previously shared items
  • Access patterns where the same user repeatedly retrieves delta data shortly after share removal events

Detection Strategies

  • Correlate Joplin Server application logs with share permission changes to identify delta API calls referencing items the requester no longer has access to
  • Monitor for delta responses containing item payloads for users with recently revoked share entitlements
  • Inspect Joplin Server audit logs for repeated delta requests from accounts that have been removed from notebook shares

Monitoring Recommendations

  • Enable verbose logging on the /api/changes and delta endpoints to capture requester identity and returned item identifiers
  • Forward Joplin Server logs to a centralized log analytics platform for retention and correlation with share lifecycle events
  • Alert on unexpected access to note content by users whose share permissions were recently modified

How to Mitigate CVE-2026-34600

Immediate Actions Required

  • Upgrade Joplin Server to version 3.5.3 or later, which contains the fix for both the delta authorization gap and the compression logic flaw
  • Audit recent share revocations and review delta API access logs for accounts that may have retrieved revoked notes
  • Rotate or revise note content that may have been disclosed to users whose access was previously revoked

Patch Information

The vulnerability is fixed in Joplin version 3.5.3. The fix addresses both the missing authorization check in ChangeModel.delta and the unsafe create-delete compression behavior. Review the GitHub Pull Request #14289 and the GitHub Issue #14110 for the upstream discussion of the prior incomplete fix and the additional remediation applied in 3.5.3.

Workarounds

  • If immediate upgrade is not possible, disable the DELTA_INCLUDES_ITEMS option so that the delta API does not attach the latest item state to responses
  • Limit share usage on sensitive notebooks until the server is upgraded to 3.5.3
  • Restrict network access to the Joplin Server delta endpoints to trusted clients while remediation is pending
bash
# Configuration example: disable item payloads in delta responses
# Set the following environment variable before starting Joplin Server
export DELTA_INCLUDES_ITEMS=0

# Then restart the service
systemctl restart joplin-server

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeInformation Disclosure

  • Vendor/TechJoplin

  • SeverityMEDIUM

  • CVSS Score5.7

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-200
  • Technical References
  • GitHub Issue Discussion

  • GitHub Pull Request

  • GitHub Security Advisory
  • Related CVEs
  • CVE-2025-57798: Joplin Note-Taking App DoS Vulnerability

  • CVE-2026-22810: Joplin Path Traversal Vulnerability

  • CVE-2025-27409: Joplin Server Path Traversal Vulnerability

  • CVE-2025-24028: Joplin Note-Taking App XSS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English