Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.com/scripta/escriptorium/-/work_items/1229 |
|
History
Thu, 06 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check | |
| Title | Missing Authorization in eScriptorium | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-08-06T15:47:06.237Z
Reserved: 2026-07-29T17:05:33.317Z
Link: CVE-2026-18276
Updated: 2026-08-06T15:47:03.025Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T17:00:11Z