CVE-2026-52111

An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey

  • Published Sep 1, 2026
  • CVSS 9.8 critical
  • 0.6% chance of exploitation in the next 30 days (EPSS)

CVE-2026-52111 at the National Vulnerability Database