Description
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
Published: 2026-08-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the WebSocket consumer of Scripta eScriptorium allows an authenticated user to subscribe to any document’s event stream without permission checks. By sending a join‑room message, the attacker can observe another user’s segmentation, transcription, import, export, and training activity, exposing potentially sensitive data. The flaw is a classic missing authorization weakness (CWE‑862).

Affected Systems

Vulnerable versions include Scripta eScriptorium 26.04.1. The issue is fixed in 26.04.2, 1.0.1, and 0.13.9. The affected product is the WebSocket consumer component that processes join‑room messages in the eScriptorium application.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote authenticated session; an attacker with any valid user credentials can trigger the flaw and view other users’ activity streams, compromising confidentiality.

Generated by OpenCVE AI on August 6, 2026 at 16:57 UTC.

Remediation

Vendor Solution

Upgrade to fixed version: 26.04.2, 1.0.1 or 0.13.9.


OpenCVE Recommended Actions

  • Upgrade eScriptorium to 26.04.2, 1.0.1, or 0.13.9 to remove the missing authorization check.
  • Enforce role‑based access control so that only users with explicit document permissions can subscribe to its event stream via the WebSocket endpoint.
  • Audit recent WebSocket activity logs to detect any unauthorized subscriptions and revoke privileges as needed.

Generated by OpenCVE AI on August 6, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Escriptorium
Escriptorium escriptorium
CPEs cpe:2.3:a:escriptorium:escriptorium:*:*:*:*:*:*:*:*
Vendors & Products Escriptorium
Escriptorium escriptorium

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Scripta
Scripta escriptorium
Vendors & Products Scripta
Scripta escriptorium

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
Title Missing Authorization in eScriptorium
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Escriptorium Escriptorium
Scripta Escriptorium
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-06T15:47:06.237Z

Reserved: 2026-07-29T17:05:33.317Z

Link: CVE-2026-18276

cve-icon Vulnrichment

Updated: 2026-08-06T15:47:03.025Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-06T16:16:37.977

Modified: 2026-08-18T18:05:23.830

Link: CVE-2026-18276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:29Z

Weaknesses