CVE-2026-18276
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to a
CVSS
4.3
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-862
Not enough EPSS history yet.
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-182777.1 HIG—
———Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path6hCVE-2026-667127.5 HIG—
———Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.6hCVE-2026-667088.2 HIG—
———Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.7hCVE-2026-667015.3 MED—
———Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.7hCVE-2026-666995.3 MED—
———Custom role Broken Access Control in Dokan <= 5.0.10 versions.7hCVE-2026-666784.3 MED—
———Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.7h