PT-2026-70834 · Cvat · Cvat
CVE-2026-73219
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.17.0 through 2.71.0
Description
A user with write access to a job can submit a batch automatic annotation request to the 'RequestViewSet.create' endpoint using inconsistent task and job IDs. Since the task ID determines the single active request slot, this action can block automatic annotation for another task if its ID is known.
Recommendations
Update to version 2.72.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvat