Tag Management Vulnerability in Papra Document Management Platform
CVE-2026-48052

5.4MEDIUM

Key Information:

Vendor

Papra-hq

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-48052?

Prior to version 26.5.0, the Papra document management platform had a flaw that allowed authenticated users to delete or rename tags belonging to different organizations. This vulnerability arose because the application inadequately correlated the URL-level organization restrictions with database operations. Specifically, the routing mechanism checked membership based on organization IDs in the URL, but the database actions were reliant solely on tag IDs, bypassing the intended organizational scope and compromising data integrity. This issue has since been addressed in version 26.5.0.

Affected Version(s)

papra < 26.5.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.