CVE-2026-73221: Vulnerability in CVAT Affects Open Source Annotation Tool
CVE-2026-73221

5.3MEDIUM

Key Information:

Vendor

Cvat-ai

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73221?

CVAT, an open-source tool for interactive video and image annotation, suffers from an improper access control issue. Users assigned the Worker role can exploit predictable task-based request IDs to gain unauthorized visibility into automatic annotation requests, including tasks or jobs they do not possess access to. Furthermore, affected users can cancel requests initiated by others, potentially disrupting the workflow. This vulnerability has been addressed in CVAT version 2.72.0, emphasizing the need for users to upgrade to this release to maintain security.

Affected Version(s)

cvat >= 2.17.0, < 2.72.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.