Impact
Missing authorization in the WebSocket consumer of Scripta eScriptorium allows an authenticated user to subscribe to any document’s event stream without permission checks. By sending a join‑room message, the attacker can observe another user’s segmentation, transcription, import, export, and training activity, exposing potentially sensitive data. The flaw is a classic missing authorization weakness (CWE‑862).
Affected Systems
Vulnerable versions include Scripta eScriptorium 26.04.1. The issue is fixed in 26.04.2, 1.0.1, and 0.13.9. The affected product is the WebSocket consumer component that processes join‑room messages in the eScriptorium application.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote authenticated session; an attacker with any valid user credentials can trigger the flaw and view other users’ activity streams, compromising confidentiality.
OpenCVE Enrichment