PT-2026-65083 · Papra · Papra
CVE-2026-48052
·
Published
2026-07-27
·
Updated
2026-07-27
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Papra versions prior to 26.5.0
Description
An authenticated user who is a member of any organization can delete or rename tags belonging to a different organization if they possess the target tag's ID. This occurs because the route handler verifies the caller's membership of the
:organizationId in the URL, but the repository write operation filters based only on the tag.id, causing the organization scope defined in the URL to be ignored by the database.Recommendations
Update to version 26.5.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Papra