CVE-2026-35462

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:40

Type Values Removed Values Added
References () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - Vendor Advisory, Exploit () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - Exploit, Vendor Advisory

24 Apr 2026, 15:22

Type Values Removed Values Added
References () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - () https://github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5 - Vendor Advisory, Exploit
CPE cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:*
First Time Papra
Papra papra

07 Apr 2026, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 15:17

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35462

Mitre link : CVE-2026-35462

CVE.ORG link : CVE-2026-35462


JSON object : View

Products Affected

papra

  • papra
CWE
CWE-613

Insufficient Session Expiration