LOWVulnerability

CVE-2026-73221

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with the Worker role can use predictable task-based request IDs with the lambda request retrieve and destroy endpoints to view automatic annotation requests for tasks or jobs the user cannot access and cancel requests initiated by other users. This issue is fixed in version 2.72.0.

Properties

epss_score
0.00246
cve_id
CVE-2026-73221
published_at
2026-08-11T19:18:51.583
last_modified
2026-09-10T20:36:14.340
epss_percentile
0.15838

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73221 — Ninja Signal Threat Intelligence | Ninja Signal