4.3
CVE-2026-18276
- EPSS 0.27%
- Veröffentlicht 06.08.2026 15:11:03
- Zuletzt bearbeitet 18.08.2026 18:05:23
- CVE-Watchlists
- Unerledigt
Missing Authorization in eScriptorium
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Escriptorium ≫ Escriptorium Version <= 26.04.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.182 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://gitlab.com/scripta/escriptorium/-/work_items/1229