Improper Access Control in Doccano Open Source Annotation Tools for Machine Learning
CVE-2026-82833
Key Information:
- Vendor
Doccano
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82833?
A vulnerability exists in Doccano Open Source Annotation Tools that affects the Project Example Detail Endpoint in versions up to 1.8.5. This flaw allows unauthorized access due to improper access controls in the ExampleDetail function of the endpoint located at /v1/projects/1/examples/. Given that the exploit is publicly available, it poses a significant risk, as attackers may launch remote exploitation attempts. Despite early notifications to the vendor about this issue, there has been no response or remediation action taken.
Affected Version(s)
Auto Labeling Pipeline Module to Annotate a Document Automatically 1.8.0
Auto Labeling Pipeline Module to Annotate a Document Automatically 1.8.1
Auto Labeling Pipeline Module to Annotate a Document Automatically 1.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
