CVE-2026-76073: Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset

Published Aug 24, 2026
·
Updated

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in labelstudio/tasks/api.py declares queryset = Annotation.objects.all() and provides no getqueryset override, so the default lookup retrieves any annotation by primary key. The view's permissionrequired entries name annotations.view, annotations.change and annotations.delete, and labelstudio/core/permissions.py registers every permission with rules.isauthenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with projectorganization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file.

Affected Software

1 affected component
Label Studio Label Studio<=1.23.0

Event History

Aug 24, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Label Studio user on a shared instance can exploit it, including a user belonging to a different organization. The attacker needs only a valid account and annotation primary-key values; no additional privileges or user interaction are required.

2

What can an attacker do with another organization's annotations?

An attacker can enumerate sequential annotation identifiers and use the annotation detail endpoint to read, modify, or delete annotations belonging to other organizations. The unscoped queryset is also present in AnnotationConvertAPI.

3

Are organizations protected by the existing permission checks?

No. The relevant view permissions are registered for any authenticated user, and the affected endpoint does not perform an object-level check that the annotation belongs to the requester's active organization.

4

How can administrators determine whether their instance is affected?

Instances running Label Studio through 1.23.0 are affected according to the available information. Review label_studio/tasks/api.py for AnnotationAPI or AnnotationConvertAPI using Annotation.objects.all() without a queryset restriction to the requester's organization.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203