PT-2026-65083 · Papra · Papra

CVE-2026-48052

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Papra versions prior to 26.5.0
Description An authenticated user who is a member of any organization can delete or rename tags belonging to a different organization if they possess the target tag's ID. This occurs because the route handler verifies the caller's membership of the :organizationId in the URL, but the repository write operation filters based only on the tag.id, causing the organization scope defined in the URL to be ignored by the database.
Recommendations Update to version 26.5.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48052
GHSA-WRX4-3VFF-JM94

Affected Products

Papra