CVE-2026-58373: CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence

Published Jun 30, 2026
·
Updated

CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.getqueryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing checkobjectpermissions call on the parentid query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parentid values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content.

Affected Software

2 affected components
CVAT CVAT<2.69.0
CVAT Computer Vision Annotation Tool<2.69.0

Event History

Jun 30, 2026
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58373?

The severity of CVE-2026-58373 is rated as medium with a score of 4.3.

2

How do I fix CVE-2026-58373?

To fix CVE-2026-58373, update your CVAT software to version 2.69.0 or later.

3

What does CVE-2026-58373 exploit?

CVE-2026-58373 exploits a missing authorization check on the parent_id filter, allowing attackers to view reports from other organizations.

4

Who is affected by CVE-2026-58373?

Authenticated users of CVAT versions prior to 2.69.0 are affected by CVE-2026-58373.

5

What types of attacks can CVE-2026-58373 enable?

CVE-2026-58373 can enable attackers to enumerate quality report identifiers from other organizations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203