CVE-2026-18258

Source
https://cve.org/CVERecord?id=CVE-2026-18258
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18258.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18258
Published
2026-08-06T15:11:28Z
Modified
2026-09-25T03:46:29Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Authorization Bypass Through User-Controlled Key in eScriptorium
Details

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18258.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "26.4.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "26.04.1"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / gitlab.com/scripta/escriptorium

Affected ranges

Type
GIT
Repo
https://gitlab.com/scripta/escriptorium
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe": "cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "26.04.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

26.*
26.04b1
base-0.*
base-0.10.1b
base-0.10.5
base-0.12.2
base-0.12.2b
base-0.13.7-revert-pyes
base-0.13.8-django-4.1
Other
base-dj-solo
base-django42
base-kraken42
base-kraken4312
base-kraken435
base-kraken439
base-kraken439b
base-kraken7
dev-new-ui-alpha
dev-new-ui-alpha-rev1
dev-new-ui-alpha-rev2
dev-new-ui-alpha-rev3
dev-new-ui-alpha-rev4
dev-new-ui-alpha-rev5
dev-new-ui-alpha-rev6
dev-new-ui-alpha-rev7
dev-new-ui-alpha-rev8
dev-pre-release
dev-revert-pyes
dev-staging
dev-0.*
dev-0.14.2
dev-beta-0.*
dev-beta-0.14
dev-beta-0.14.1
dev0.*
dev0.13.1c
dev0.13.3
dev0.13.3b
dev0.13.3c
dev0.13.3d
v0.*
v0.12.1-dev
v0.12.2
v0.12.2b
v0.2
v0.3
v0.4
v0.4.1
v0.5
v0.5.1
v0.5.1b
v0.5.1c
v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18258.json"