CVE-2026-35462

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
Configurations

No configuration.

History

07 Apr 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 15:17

Updated : 2026-04-08 21:27


NVD link : CVE-2026-35462

Mitre link : CVE-2026-35462

CVE.ORG link : CVE-2026-35462


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration