PatchSiren debrief for CVE-2026-18277 based on limited source detail. The CVE record was published on 2026-08-06T16:16:38.100Z and has not been modified since then. This CVE describes a vulnerability in Scripta eScriptorium through version 26.04.1, where missing authorization in the OcrModelRight create and delete views allows a remote authenticated user to grant themselves access to another user's privat [truncated]
The CVE-2026-18276 vulnerability in Scripta eScriptorium's websocket consumer allows remote authenticated users to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export, and training activity due to a missing authorization check in the websocket consumer, which fails to validate user permissions before allowing access to event streams. This issue w [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T16:16:37.853Z and has not been modified since then. The process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 have an authorization bypass vulnerability allowing remote authenticated users to run segmentation and transcription against other users' document parts, pot [truncated]
An authorization bypass vulnerability exists in the Line, LineTranscription, VirtualCollection, tag, and process API endpoints in Scripta/eScriptorium through version 26.04.1. This vulnerability allows a remote authenticated user to read, modify, and delete other users' transcription content by supplying primary keys in the request body, which are then queried against the global model manager instead of t [truncated]