CVE-2026-18258
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/08/2026
Última modificación:
18/08/2026
Descripción
*** Pendiente de traducción *** Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
Impacto
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:* | 26.04.1 (incluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



