PT-2026-30855 · Papra Hq · Papra

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35462

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — regardless of its expiration date — is accepted indefinitely, allowing a user whose key has expired to continue accessing all protected endpoints as if the key were still valid. This vulnerability is fixed in 26.4.0.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2026-35462

Affected Products

Papra