CVE-2026-58373
CVE-2026-58373 is a medium-severity vulnerability in Cvat Computer Vision Annotation Tool with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (25th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-862
- Affected product: Cvat Computer Vision Annotation Tool
- Published:
- Last modified:
Description
CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parent_id values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content.
Frequently asked questions
- What is CVE-2026-58373?
- CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parent_id values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content.
- How severe is CVE-2026-58373?
- CVE-2026-58373 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2026-58373 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (25th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-58373?
- CVE-2026-58373 affects Cvat Computer Vision Annotation Tool. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-58373?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-58373 published?
- CVE-2026-58373 was published on 2026-06-30 and last updated on 2026-07-14.
References
- https://github.com/cvat-ai/cvat/commit/27953f19d2265f8b495369f816730a7452db791b
- https://github.com/cvat-ai/cvat/pull/10807
- https://github.com/cvat-ai/cvat/releases/tag/v2.69.0
- https://www.vulncheck.com/advisories/cvat-missing-authorization-on-quality-reports-parent-id-filter-leaks-cross-organization-report-existence
Affected products (1)
- cpe:2.3:a:cvat:computer_vision_annotation_tool:*:*:*:*:*:*:*:*
More vulnerabilities in Cvat Computer Vision Annotation Tool
- CVE-2025-23045 — Critical (CVSS 9.8): Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An…
- CVE-2021-45046 — Critical (CVSS 9.0): It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default…
- CVE-2026-23526 — High (CVSS 8.8): CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through…
- CVE-2022-31188 — High (CVSS 8.6): CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were…
- CVE-2024-37306 — High (CVSS 7.1): Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting…
- CVE-2024-37164 — High (CVSS 7.1): Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT…
All CVEs affecting Cvat Computer Vision Annotation Tool →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-101000 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
- CVE-2026-97360 — Critical (CVSS 10.0): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows…
- CVE-2026-65381 — Critical (CVSS 10.0): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the…
- CVE-2026-81648 — Critical (CVSS 10.0): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX…
- CVE-2026-77770 — Critical (CVSS 10.0): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a…
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-862 (Missing Authorization) vulnerabilities →