CVE-2026-85211
Received Received - Intake

Label Studio Cloud Storage URI Access Bypass via Organization Filter Bypass

Vulnerability report for CVE-2026-85211, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
humansignal label_studio 1.23.0
humansignal label_studio to 1.23.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Label Studio does not enforce organization-specific filters when resolving storage URIs for tasks and projects. This allows attackers to access other tenants' cloud storage objects by creating a separate organization and providing arbitrary file URIs to presign or stream bucket contents.

Impact Analysis

Attackers could access sensitive data stored in cloud buckets belonging to other organizations. This may lead to unauthorized data exposure, data leaks, or compliance violations depending on the stored information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information.

Mitigation Strategies

Update Label Studio to the latest version to ensure the organization filters are properly applied in proxy_api.py endpoints. Review and restrict access controls for cloud storage objects to prevent unauthorized tenant access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85211. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart