HIGH
CVE-2026-18258
CVSS
8.8
Description
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.