Authentication Bypass Vulnerability in Papra Document Management System
CVE-2026-35462
4.3MEDIUM
What is CVE-2026-35462?
The Papra document management and archiving platform has a significant vulnerability where API keys with an expiration date are not validated against the current time during authentication. This flaw permits any API key, regardless of its expiration status, to be accepted indefinitely. As a result, users with expired keys can continue to access sensitive endpoints, raising serious concerns regarding data security and integrity. This issue is resolved in version 26.4.0 of the platform. For more information, refer to Papra Security Advisory.
Affected Version(s)
papra < 26.4.0
