CVE-2026-76073: Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in labelstudio/tasks/api.py declares queryset = Annotation.objects.all() and provides no getqueryset override, so the default lookup retrieves any annotation by primary key. The view's permissionrequired entries name annotations.view, annotations.change and annotations.delete, and labelstudio/core/permissions.py registers every permission with rules.isauthenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with projectorganization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated Label Studio user on a shared instance can exploit it, including a user belonging to a different organization. The attacker needs only a valid account and annotation primary-key values; no additional privileges or user interaction are required.
What can an attacker do with another organization's annotations?
An attacker can enumerate sequential annotation identifiers and use the annotation detail endpoint to read, modify, or delete annotations belonging to other organizations. The unscoped queryset is also present in AnnotationConvertAPI.
Are organizations protected by the existing permission checks?
No. The relevant view permissions are registered for any authenticated user, and the affected endpoint does not perform an object-level check that the annotation belongs to the requester's active organization.
How can administrators determine whether their instance is affected?
Instances running Label Studio through 1.23.0 are affected according to the available information. Review label_studio/tasks/api.py for AnnotationAPI or AnnotationConvertAPI using Annotation.objects.all() without a queryset restriction to the requester's organization.