CVE-2026-52111
An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey
- Published Sep 1, 2026
- CVSS 9.8 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)