PT-2026-68609 · Scripta · Escriptorium

CVE-2026-18258

·

Published

2026-08-06

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scripta/eScriptorium versions prior to 26.04.2
Description An authorization bypass exists in the 'Line', 'LineTranscription', 'VirtualCollection', 'tag', and 'process' API endpoints. This issue allows a remote authenticated user to read, modify, and delete transcription content belonging to other users. The flaw occurs because primary keys provided in the request body are queried against the global model manager instead of the request-scoped queryset, which is the filtered set of data the user is actually authorized to access.
Recommendations Update Scripta/eScriptorium to version 26.04.2 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18258

Affected Products

Escriptorium