CVE-2026-18258

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-06 16:16

Updated : 2026-08-18 18:05


NVD link : CVE-2026-18258

Mitre link : CVE-2026-18258

CVE.ORG link : CVE-2026-18258


JSON object : View

Products Affected

escriptorium

  • escriptorium
CWE
CWE-639

Authorization Bypass Through User-Controlled Key