cvedb.io
CVE-2025-27134
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2025-04-30T15:16:00.927 · Last modified 2026-06-17T09:03:04.533

Summary

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint `PATCH /api/users/:id` to set the `is_admin` field to 1. The vulnerability allows malicious low-privileged users to perform administrative actions without proper authorization. This issue has been patched in version 3.3.3.

Affected products

joplin_project — joplin

Does this affect you?

Add your gear to cvedb and we'll alert you only when joplin_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.