Executive brief
CVAT is an open-source tool used for annotating data for computer vision and machine learning. A security flaw in the quality reporting system allows logged-in users to discover the existence of reports belonging to other organizations. While the actual content of the reports is not exposed, this leak allows unauthorized users to map out private project identifiers across the platform.
Technical details
An improper authorization vulnerability exists in `QualityReportViewSet.get_queryset` due to a missing `check_object_permissions` call on the `parent_id` query parameter. Authenticated attackers can perform a side-channel attack by sending requests with sequential integer `parent_id` values. The API distinguishes between existing and non-existing reports by returning an HTTP 500 error for inaccessible existing reports versus an HTTP 404 for non-existent ones. This allows for cross-organization resource enumeration, though it does not grant access to the report content itself. The issue is resolved in version 2.69.0.
Affected products
- cvat-ai CVAT < 2.69.0
Timeline
- 2026-06-19: patched: Fix merged into develop branch
- 2026-06-22: advisory: Release v2.69.0 published
- 2026-06-30: disclosed: CVE published
References
- https://github.com/cvat-ai/cvat/commit/27953f19d2265f8b495369f816730a7452db791b
- https://github.com/cvat-ai/cvat/pull/10807
- https://github.com/cvat-ai/cvat/releases/tag/v2.69.0
- https://www.vulncheck.com/advisories/cvat-missing-authorization-on-quality-reports-parent-id-filter-leaks-cross-organization-report-existence