CVE-2026-73221
Received Received - Intake

Arbitrary Task Request Access in CVAT

Vulnerability report for CVE-2026-73221, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: GitHub, Inc.

Description

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests for tasks or jobs the user cannot access and cancel requests initiated by other users. This issue is fixed in version 2.72.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
cvat_ai cvat From 2.17.0 (inc) to 2.72.0 (exc)
cvat_ai cvat 2.72.0
cvat_ai cvat to 2.72.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73221 is an insufficient authorization vulnerability in CVAT versions 2.17.0 to 2.71.0. A user with the Worker role can exploit predictable task-based request IDs to view or cancel automatic annotation requests for tasks they cannot access and cancel requests made by other users.

Detection Guidance

To detect this vulnerability, check CVAT versions between 2.17.0 and 2.71.0. Verify if unauthorized users can access or cancel lambda requests using predictable task IDs. Monitor logs for suspicious activity related to lambda request endpoints.

Impact Analysis

This vulnerability allows low-privileged users to access and manipulate automatic annotation requests, potentially viewing sensitive data or disrupting annotation tasks. It impacts confidentiality and integrity but does not affect system availability.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized access to sensitive annotation data. A low-privileged user could view or cancel automatic annotation requests for tasks they do not own, potentially exposing personal or protected health information. This violates principles of data confidentiality and integrity required by these regulations.

Mitigation Strategies

Upgrade CVAT to version 2.72.0 or later to address the authorization issues in lambda request endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73221. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart