8.8
CVE-2026-18258
- EPSS 0.31%
- Veröffentlicht 06.08.2026 15:11:28
- Zuletzt bearbeitet 18.08.2026 18:05:06
- CVE-Watchlists
- Unerledigt
Authorization Bypass Through User-Controlled Key in eScriptorium
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Escriptorium ≫ Escriptorium Version <= 26.04.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.234 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://gitlab.com/scripta/escriptorium/-/work_items/1226