PT-2026-68611 · Scripta · Escriptorium
CVE-2026-18276
·
Published
2026-08-06
·
Updated
2026-08-18
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Scripta eScriptorium versions prior to 26.04.2
Description
Missing authorization in the websocket consumer allows a remote authenticated user to subscribe to the event stream of any document. This occurs because the
object cls and object pk values of a join-room message are passed to the group add() function without an access check, enabling the observer to monitor another user's segmentation, transcription, import, export, and training activity.Recommendations
Update Scripta eScriptorium to version 26.04.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Escriptorium