CVE-2026-52111: Fast-note-sync-service vulnerability
Published Sep 1, 2026
·Updated
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
Affected Software
1 affected component
fast-note-sync-service<=2.13.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
fast-note-sync-serviceto a version that resolves this vulnerability.Fixed in 2.13.7
Event History
Sep 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
How can I identify deployments that need remediation?
Treat any fast-note-sync-service deployment running version 2.13.7 or earlier as affected.
2
What level of attacker access is indicated?
The issue is described as remotely exploitable through the admin configuration endpoint. The available information does not specify whether prior authentication is required.