Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-18258

Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 23.8%
CVSS Severity
CVSS v3 Score 8.8


Contact Us

Shodan ® - All rights reserved