CVE-2026-18276: Missing Authorization in eScriptorium
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the objectcls and objectpk values of a join-room message, which are passed to groupadd without an access check
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.04.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.13.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18276?
The severity of CVE-2026-18276 is medium, with a CVSS score of 4.3.
How do I fix CVE-2026-18276?
To fix CVE-2026-18276, ensure proper authorization checks are implemented in the websocket consumer for event stream subscriptions.
What type of vulnerability is CVE-2026-18276?
CVE-2026-18276 is a missing authorization vulnerability affecting the Scripta eScriptorium system.
Who is affected by CVE-2026-18276?
Remote authenticated users of Scripta eScriptorium are affected by CVE-2026-18276.
What can an attacker do with CVE-2026-18276?
An attacker can observe another user's document activities, including segmentation and transcription processes, due to the missing authorization.