AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18258

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows remote authenticated users to bypass authorization controls in the Scripta/eScriptorium API, enabling them to read, modify, and delete other users' transcription content by manipulating primary keys in the request body. This could lead to significant data breaches and unauthorized access to sensitive information. Organizations using affected versions should prioritize patching this issue to protect user data and maintain compliance.

CVE
CVE-2026-18258
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset