PT-2026-67829 · Cvat · Cvat

CVE-2026-47682

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CVAT versions 1.6.0 through 2.64.0
Description An attacker with write access to a cloud storage added to a CVAT instance, or the ability to add new cloud storages, can overwrite arbitrary files on the server's filesystem.
Recommendations Update to version 2.65.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47682
GHSA-6F87-4G86-P9GW

Affected Products

Cvat