PT-2026-68612 · Scripta · Escriptorium

CVE-2026-18277

·

Published

2026-08-06

·

Updated

2026-08-18

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Scripta eScriptorium versions prior to 26.04.2
Description Missing authorization in the OcrModelRight create and delete views allows a remote authenticated user to grant themselves access to another user's private OCR model or revoke any user's OCR model access via a POST request. This occurs because the ownership check is implemented within the get context data() function, which only executes during the GET rendering path, leaving the POST request path unprotected.
Recommendations Update Scripta eScriptorium to version 26.04.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18277

Affected Products

Escriptorium