Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
References
| Link | Resource |
|---|---|
| https://gitlab.com/scripta/escriptorium/-/work_items/1226 | Permissions Required |
Configurations
History
No history.
Information
Published : 2026-08-06 16:16
Updated : 2026-08-18 18:05
NVD link : CVE-2026-18258
Mitre link : CVE-2026-18258
CVE.ORG link : CVE-2026-18258
JSON object : View
Products Affected
escriptorium
- escriptorium
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
