CVE-2026-35462 is an authentication bypass vulnerability affecting Papra, a document management and archiving platform, in versions prior to 26.4.0. The flaw stems from insufficient validation of API key expiration dates during the authentication process, allowing expired API keys to remain valid indefinitely and grant continued access to all protected endpoints. The vulnerability presents a medium severity risk with a CVSS score of 4.3, exploitable over the network with low complexity and requiring low privileges (an existing valid user account). The attack surface is limited to confidentiality impacts, with no integrity or availability concerns noted. The EPSS score of 0.00034 indicates minimal observed exploitation activity compared to other vulnerabilities. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. There is no public exploit code readily available, and community attention remains low based on its inactive status on threat tracking lists. Organizations using Papra should prioritize upgrading to version 26.4.0 or later to remediate this authentication weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.4.0CPE matchmatch criteria | cpe:2.3:a:papra:papra:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.