CVE-2026-18258
Analyzed Analyzed - Analysis Complete

Authorization Bypass in Scripta/eScriptorium API Endpoints

Vulnerability report for CVE-2026-18258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-18

Assigner: GitLab Inc.

Description

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-18
Generated
2026-08-27
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
escriptorium escriptorium to 26.04.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Scripta/eScriptorium versions up to 26.04.1. It affects multiple API endpoints including Line, LineTranscription, VirtualCollection, tag, and process. A remote authenticated user can exploit this to read, modify, or delete other users' transcription content by supplying primary keys in the request body. The issue occurs because the system queries the global model manager instead of the request-scoped queryset, allowing unauthorized access.

Detection Guidance

This vulnerability involves authorization bypass in Scripta/eScriptorium endpoints. To detect it, inspect API requests to Line, LineTranscription, VirtualCollection, tag, and process endpoints for improper primary key handling. Check if requests use global model manager queries instead of request-scoped querysets. Monitor for unauthorized read, modify, or delete operations on user transcription content.

Impact Analysis

If you are an authenticated user of Scripta/eScriptorium, an attacker with your credentials or access could read, alter, or delete your transcription content and that of other users. This could lead to data loss, unauthorized modifications, or exposure of sensitive information. The high CVSS score (8.8) indicates a significant risk of exploitation.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of user data, violating GDPR's principles of data integrity and confidentiality. For HIPAA, it may result in unauthorized disclosure or alteration of protected health information, potentially breaching compliance requirements. Organizations using this software should address it promptly to avoid regulatory penalties.

Mitigation Strategies

Update Scripta/eScriptorium to version 26.04.1 or later to address the authorization bypass vulnerability in the affected API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart