CVE-2025-27134
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 284
Summary
CVE-2025-27134 is a privilege escalation vulnerability affecting the Joplin note-taking application before version 3.3.3. The issue lies in the Joplin server's API endpoint `PATCH /api/users/:id`. Malicious non-admin users could exploit this endpoint to set the `is_admin` field to 1, granting them administrative privileges. This vulnerability enables unauthorized users to perform administrative actions within the application. The issue has been resolved in Joplin version 3.3.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.