Vulnerability Description
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Papra | Papra | < 26.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5Vendor AdvisoryExploit
FAQ
What is CVE-2026-35462?
CVE-2026-35462 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — r...
How severe is CVE-2026-35462?
CVE-2026-35462 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35462?
Check the references section above for vendor advisories and patch information. Affected products include: Papra Papra.