Authorization Bypass in jsbroks COCO Annotator's Dataset API
CVE-2026-7681

6.9MEDIUM

Key Information:

Vendor

Jsbroks

Vendor
CVE Published:
3 May 2026

What is CVE-2026-7681?

A security vulnerability exists in the jsbroks COCO Annotator up to version 0.11.1, affecting the Dataset API functionality located in backend/webserver/api/datasets.py. This flaw permits manipulation of the DatasetId argument, allowing unauthorized access and modification of datasets. The vulnerability can be exploited remotely, posing significant risks to data integrity. Despite earlier contact attempts regarding this issue, the vendor has not provided any response, highlighting the urgency for users to secure their applications.

Affected Version(s)

COCO Annotator 0.11.0

COCO Annotator 0.11.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nmmorette (VulDB User)
VulDB CNA Team
.