CVE-2026-73221
CVAT: Flawed authorization logic in endpoints related to lambda requests
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests for tasks or jobs the user cannot access and cancel requests initiated by other users. This issue is fixed in version 2.72.0.
| CWE | CWE-863 |
| Vendor | cvat-ai |
| Product | cvat |
| Published | Aug 11, 2026 |
| Last Updated | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for cvat-ai cvat
Be the first to know when new unknown vulnerabilities affecting cvat-ai cvat are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
cvat-ai / cvat
>= 2.17.0, < 2.72.0