AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18275

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability allows a remote authenticated user to bypass authorization controls in Scripta eScriptorium, enabling them to access and modify document parts belonging to other users. This could lead to unauthorized content overwriting, compromising data integrity and confidentiality. Organizations using this software should prioritize addressing this issue to protect user data and maintain trust.

CVE
CVE-2026-18275
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect