CVE-2024-35184: Paperless-Ngx

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.

Affected products

  • Paperless-Ngx Paperless-Ngx: from 2.5.0, before 2.8.6 (fixed in 2.8.6)

Published 2024-05-15. Last modified 2026-06-17.