Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to fixed version: 26.04.2, 1.0.1 or 0.13.9.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gitlab.com/scripta/escriptorium/-/work_items/1228 |
|
History
Thu, 06 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect | |
| Title | Authorization Bypass Through User-Controlled Key in eScriptorium | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-08-06T15:11:08.255Z
Reserved: 2026-07-29T17:05:28.661Z
Link: CVE-2026-18275
Updated: 2026-08-06T15:46:43.167Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T16:45:07Z
Weaknesses