CVE-2026-73221: CVAT: Flawed authorization logic in endpoints related to lambda requests
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests for tasks or jobs the user cannot access and cancel requests initiated by other users. This issue is fixed in version 2.72.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cvatto a version that resolves this vulnerability.Fixed in 2.72.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73221?
The severity of CVE-2026-73221 is rated at risk level 47.
What does CVE-2026-73221 affect?
CVE-2026-73221 affects the CVAT software versions from 2.17.0 to 2.72.0.
How do I fix CVE-2026-73221?
To fix CVE-2026-73221, update CVAT to a version that is higher than 2.72.0.
What type of vulnerability is CVE-2026-73221?
CVE-2026-73221 is a flaw in the authorization logic related to lambda requests.
Who is at risk with CVE-2026-73221?
Users with the Worker role in CVAT are at risk due to flawed authorization logic.