Authentication Bypass Vulnerability in Papra Document Management System
CVE-2026-35462

4.3MEDIUM

Key Information:

Vendor

Papra-hq

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-35462?

The Papra document management and archiving platform has a significant vulnerability where API keys with an expiration date are not validated against the current time during authentication. This flaw permits any API key, regardless of its expiration status, to be accepted indefinitely. As a result, users with expired keys can continue to access sensitive endpoints, raising serious concerns regarding data security and integrity. This issue is resolved in version 26.4.0 of the platform. For more information, refer to Papra Security Advisory.

Affected Version(s)

papra < 26.4.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.