{"id":"CVE-2026-41571","summary":"Note Mark: OIDC-registered users authenticated by submitting password \"null\"","details":"Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt(\"null\") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: \"null\" to the internal login endpoint receives a valid session for that user. The bypass is unauthenticated and requires no user interaction. This issue has been patched in version 0.19.3.","aliases":["GHSA-pxf8-6wqm-r6hh","GO-2026-5557"],"modified":"2026-08-04T11:49:29.152748048Z","published":"2026-05-04T17:42:32.428Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41571.json"},"references":[{"type":"WEB","url":"https://github.com/enchant97/note-mark/releases/tag/v0.19.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41571.json"},{"type":"ADVISORY","url":"https://github.com/enchant97/note-mark/security/advisories/GHSA-pxf8-6wqm-r6hh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41571"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/enchant97/note-mark","events":[{"introduced":"9f627bbb0cccebf872ec4b450ba2cd1d59ba9697"},{"last_affected":"9f627bbb0cccebf872ec4b450ba2cd1d59ba9697"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"= 0.19.2"},{"last_affected":"= 0.19.2"}]}}],"versions":["= 0.19.2","v0.19.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41571.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}