CVE-2026-73221: Vulnerability in CVAT Affects Open Source Annotation Tool
CVE-2026-73221
5.3MEDIUM
What is CVE-2026-73221?
CVAT, an open-source tool for interactive video and image annotation, suffers from an improper access control issue. Users assigned the Worker role can exploit predictable task-based request IDs to gain unauthorized visibility into automatic annotation requests, including tasks or jobs they do not possess access to. Furthermore, affected users can cancel requests initiated by others, potentially disrupting the workflow. This vulnerability has been addressed in CVAT version 2.72.0, emphasizing the need for users to upgrade to this release to maintain security.
Affected Version(s)
cvat >= 2.17.0, < 2.72.0
