PT-2026-70834 · Cvat · Cvat

CVE-2026-73219

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CVAT versions 2.17.0 through 2.71.0
Description A user with write access to a job can submit a batch automatic annotation request to the 'RequestViewSet.create' endpoint using inconsistent task and job IDs. Since the task ID determines the single active request slot, this action can block automatic annotation for another task if its ID is known.
Recommendations Update to version 2.72.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73219
GHSA-7XHX-3Q27-XVCX

Affected Products

Cvat