PT-2026-70843 · Cvat · Cvat
CVE-2026-73221
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
CVAT versions 2.17.0 through 2.71.0
Description
Flawed authorization logic allows a user with the Worker role to use predictable task-based request IDs to access unauthorized data. By interacting with the lambda request retrieve and destroy endpoints, an attacker can view automatic annotation requests for tasks or jobs they are not permitted to access and cancel requests initiated by other users.
Recommendations
Update to version 2.72.0.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cvat