PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39310 TriliumNext CVE debrief

CVE-2026-39310 is a high-severity authentication-bypass issue in Trilium Notes Desktop versions 0.102.1 and earlier. In an Electron environment, Trilium disables authentication middleware for the Clipper API, which can leave endpoints such as /api/clipper/notes reachable without a password, API token, or CSRF protection. The supplied advisory indicates that an attacker on the same network can discover exposed instances on high-range ports, confirm a candidate by querying the unauthenticated handshake endpoint, and then access note data or interact with the local application. The issue is fixed in version 0.102.2.

Vendor
TriliumNext
Product
Trilium
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-23
Advisory published
2026-05-20
Advisory updated
2026-07-23

Who should care

Anyone running Trilium Notes Desktop 0.102.1 or earlier, especially on laptops or workstations exposed to shared or untrusted networks such as corporate LANs, guest Wi-Fi, or public Wi-Fi. Security teams should also care because the flaw can expose local note data and allow unauthorized interaction with the application without any credentials.

Technical summary

The core issue is that Trilium detects an Electron environment and then disables authentication middleware for the Clipper API. According to the supplied description and advisory references, that means API endpoints including /api/clipper/notes may be exposed without authentication controls that would normally require a password, API token, or CSRF protection. The advisory also notes an unauthenticated handshake endpoint that returns the application name and protocol version, which can be used to identify a live Trilium instance. The NVD record lists CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L and weaknesses CWE-284 and CWE-306.

Defensive priority

High. This is a network-reachable authentication bypass with no privileges required and no user interaction, so exposed instances should be prioritized for upgrade and exposure review.

Recommended defensive actions

  • Upgrade Trilium Notes to version 0.102.2 or later, which the advisory identifies as the fixed release.
  • Inventory any Trilium Desktop installations running on versions 0.102.1 and earlier, with attention to systems that may be reachable from the local network.
  • Limit network exposure for Trilium-related ports on endpoints and firewalls, especially on shared or untrusted networks.
  • Verify whether any Clipper API endpoints are reachable without authentication on affected versions and treat such exposure as sensitive.
  • If immediate upgrade is not possible, isolate affected hosts from untrusted networks until remediation is complete.
  • Review local notes and application activity for unauthorized access if the service was exposed on a reachable network.

Evidence notes

The CVE record published on 2026-05-20 cites TriliumNext/Trilium release v0.102.2 and GitHub security advisory GHSA-jcvx-vc83-cppw as references. The supplied description states that versions 0.102.1 and prior are affected, that Electron mode disables authentication middleware for the Clipper API, and that the issue is fixed in 0.102.2. The NVD metadata provides the network-exposed, no-privileges CVSS vector and lists CWE-284 and CWE-306. The description also states that Trilium often binds to ports such as 37840 and that the handshake endpoint can confirm a live instance without authentication; these details are taken from the provided source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-39310 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-39310

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-39310 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39310

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.