What is CVE-2026-71244?
A vulnerability in Paperless-ngx's MailAccountViewSet.test() function allows an attacker to reuse stored passwords and tokens from an existing account by redirecting them to an attacker-controlled IMAP server, potentially compromising sensitive credentials. Users of Paperless-ngx should immediately apply the security patch.
Azərbaycanca: Paperless-ngx-in MailAccountViewSet.test() funksiyasında zəiflik aşkar edilib. Bu zəiflik imkan verir ki, təcavüzkar mövcud hesabın saxlanmış parol və token məlumatlarını öz nəzarət etdiyi IMAP serverinə yönləndirərək həssas etimadnamələri ələ keçirsin. Paperless-ngx istifadəçiləri təcili olaraq təhlükəsizlik yeniləməsini tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What is the vulnerability in Paperless-ngx that risks user credentials?
Due to a flaw in the MailAccountViewSet.test() function, an attacker can redirect stored passwords and tokens from an existing account to an attacker-controlled IMAP server, potentially compromising sensitive credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.