CVE-2026-35462

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-07 15:17

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35462

Mitre link : CVE-2026-35462

CVE.ORG link : CVE-2026-35462


JSON object : View

Products Affected

papra

  • papra
CWE
CWE-613

Insufficient Session Expiration