{"id":"CVE-2026-18276","summary":"Missing Authorization in eScriptorium","details":"Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check","modified":"2026-09-25T03:46:29.019068829Z","published":"2026-08-06T15:11:03.369Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18276.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"26.4.1"}]},{"source":"DESCRIPTION","extracted_events":[{"fixed":"26.04.1"}]}],"cna_assigner":"GitLab","cwe_ids":["CWE-862"]},"references":[{"type":"WEB","url":"https://gitlab.com/scripta/escriptorium/-/work_items/1229"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18276.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18276"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/scripta/escriptorium","events":[{"introduced":"0"},{"last_affected":"d97631d5c0279df78a26bd0611c2cf268c73202e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"26.04.1"}]}}],"versions":["v1.0.0","26.04b1","base-kraken7","dev-pre-release","base-dj-solo","dev-new-ui-alpha-rev8","dev-0.14.2","dev-new-ui-alpha-rev7","dev-new-ui-alpha-rev6","dev-new-ui-alpha-rev5","dev-beta-0.14.1","dev-new-ui-alpha-rev4","dev-new-ui-alpha-rev3","dev-beta-0.14","base-django42","dev-new-ui-alpha-rev2","dev-new-ui-alpha-rev1","dev-new-ui-alpha","dev-staging","base-0.13.8-django-4.1","dev-revert-pyes","base-0.13.7-revert-pyes","base-kraken4312","base-kraken439b","base-kraken439","base-kraken435","dev0.13.3d","dev0.13.3c","dev0.13.3b","dev0.13.3","dev0.13.1c","base-kraken42","v0.12.2b","v0.12.2","base-0.12.2b","base-0.12.2","v0.12.1-dev","base-0.10.5","base-0.10.1b","v0.5.1c","v0.5.1b","v0.5.1","v0.5","v0.4.1","v0.4","v0.3","v0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18276.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}