PT-2026-70843 · Cvat · Cvat

CVE-2026-73221

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions CVAT versions 2.17.0 through 2.71.0
Description Flawed authorization logic allows a user with the Worker role to use predictable task-based request IDs to access unauthorized data. By interacting with the lambda request retrieve and destroy endpoints, an attacker can view automatic annotation requests for tasks or jobs they are not permitted to access and cancel requests initiated by other users.
Recommendations Update to version 2.72.0.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73221
GHSA-M7P7-6W4M-886P

Affected Products

Cvat