CVE-2026-35462

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:*

History

24 Apr 2026, 15:22

Type Values Removed Values Added
References () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - Vendor Advisory, Exploit
First Time Papra
Papra papra
CPE cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:*

07 Apr 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 15:17

Updated : 2026-04-24 15:22


NVD link : CVE-2026-35462

Mitre link : CVE-2026-35462

CVE.ORG link : CVE-2026-35462


JSON object : View

Products Affected

papra

  • papra
CWE
CWE-613

Insufficient Session Expiration