What is CVE-2026-73221?
CVE-2026-73221 is a vulnerability in CVAT, an open source annotation tool, where a user with Worker role can exploit predictable task-based request IDs via lambda endpoints to view unauthorized automatic annotation requests. It affects versions 2.17.0 through 2.72.0. Upgrading to the latest patched version is recommended.
Azərbaycanca: CVE-2026-73221 CVAT açıq mənbəli annotasiya alətində Worker roluna malik istifadəçilərə, task əsaslı sorğu ID-lərindən istifadə edərək səlahiyyətləri olmayan tapşırıqların avtomatik annotasiya sorğularını görməyə imkan verən səlahiyyət zəifliyidir. Bu, 2.17.0-dan 2.72.0-a qədər olan versiyalara təsir edir. CVAT-i son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which user role in CVAT is affected by CVE-2026-73221?
This vulnerability affects users with the Worker role, allowing them to view unauthorized automatic annotation requests.
Which versions of CVAT are vulnerable to the CVE-2026-73221 authorization flaw?
CVE-2026-73221 affects CVAT versions 2.17.0 through 2.72.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.