CVE-2026-35462: Papra
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
Affected products
- Papra Papra: before 26.4.0 (fixed in 26.4.0)
Published 2026-04-07. Last modified 2026-06-17.