Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ openSUSE-SU-2026:21106-1 — papers (CVE-2026-46529)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for papers

This update for papers fixes the following issues

Security issue:

  • CVE-2026-46529: command injection (bsc#1265880).

Changes for papers:

  • Update to version 48.10 (bsc#1265880):
  • Update to version 48.9 (jsc#PED-15957, bsc#1261947):
  • Bug fixes:
  • Saved image files are empty
  • Print dialog says "Manage Custom Sizes" for Paper Size every

time

  • libview: Correct zoom in odd left dual page mode
  • Scrolling in presentation mode skips pages

+ Changes in version 48.8:

+ Bug fixes:

  • Ctrl+F sometimes does not focus search box when query is

blank

  • Page number is not in the center of the number box
  • Keyboard input unresponsive in presentation mode, unable to

exit with Esc

  • help: Update icon

+ Changes in version 48.7:

  • Fixes for the nautilus plugin filename encodings
  • shell: Fix signing when the rectangle is too small
  • libdocument: fix weak page references
  • shell: Fix opening PDFs from GVFS mounts like Google Drive

+ Changes in version 48.6:

+ Bug fixed:

  • Fix various memory leak
  • Fix several focus issues
  • Remove trailing new lines from section names
  • Migrate to xz compression and manual service run
  • Update to version 48.5:

+ Bugs fixed:

  • Preview for a link doesn't work more than once
  • Link preview triggers even after the cursor leaves the link
  • shell: fix a translation issue in printing
  • libview/pps-view: Ignore the scroll offset when drawing the

sign area

  • Selection performance
  • libview: deal with large pages
  • shell: Make sure that all child widgets of PpsView are

removed when closing document

  • Caret selection doesn't cover more than one character

+ Updated translations.

  • Update to version 48.4:
  • shell: Enable digital signing action when document supports
  • Documentation still mentions possibility of saving the

settings

  • Launch target file
  • shell: Fix signature banner title
  • Slideshow presentation is blurry
  • libview/pps-view: Do not replace the sign cursor on drag-less

movements

  • Saved annotation timestamps tooltips are shown using UTC time

in 12-hours format

  • Update to version 48.3:
  • shell: disable dual-odd-left action when dual mode is

disabled.

  • libview: Rerender annotation when the icon property is

updated

  • shell: Display the filename if the document title is only

whitespace

Affected software

openSUSE-SU-2026:21106-1 is recorded against 1 package.

  • papers (fixed in 48.10-160000.1.1)

Timeline and source

Published on 19 June 2026 and last revised on 30 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-19
Updated 2026-08-20
Modified 2026-06-30
Fix URL N/A

Affected Packages

Software From version Fixed in
papers 48.10-160000.1.1

Free Vulnerability Check

Is your site affected by openSUSE-SU-2026:21106-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2026:21106-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.