AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18276

MEDIUM · CVSS 4.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability arises from a lack of authorization in the websocket consumer of Scripta eScriptorium, allowing remote authenticated users to access and monitor the event streams of other users' documents. This exposure can lead to unauthorized observation of sensitive activities, including segmentation and transcription processes. Organizations using this software should prioritize addressing this issue to protect user privacy and prevent potential data leaks.

CVE
CVE-2026-18276
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check