What is CVE-2026-48052?
CVE-2026-48052 is a broken access control vulnerability in the Papra document management platform where any authenticated organization member can delete or rename tags of a different organization by knowing the target tag's ID. This compromises cross-organization data integrity. Upgrading Papra to version 26.5.0 or later is required to mitigate this issue.
Azərbaycanca: CVE-2026-48052 Papra sənəd idarəetmə platformasında autentifikasiya olunmuş istənilən təşkilat üzvünə, hədəf tag-in ID-sini bilmək şərtilə, başqa təşkilata məxsus tag-ləri silmək və ya adını dəyişmək imkanı verən səlahiyyət yoxlaması zəifliyidir. Bu, təşkilatlararası məlumat bütövlüyünü pozur. Təsirə məruz qalmamaq üçün Papra-nı 26.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What threat does CVE-2026-48052 pose in the Papra platform?
This vulnerability allows any authenticated organization member to delete or rename tags belonging to a different organization by knowing the target tag's ID, compromising cross-organization data integrity.
To which version should Papra be upgraded to mitigate CVE-2026-48052?
To avoid being affected, the Papra platform should be upgraded to version 26.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.