Medium severity4.3NVD Advisory· Published Apr 7, 2026· Updated Apr 24, 2026
CVE-2026-35462
CVE-2026-35462
Description
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/papra-hq/papra/security/advisories/GHSA-866c-mc22-wvv5nvdVendor AdvisoryExploit
News mentions
0No linked articles in our index yet.