Junglewise Threat Intelligence

CVE-2026-82833: Doccano improper access control in Project Example Detail Endpoint

CVE-2026-82833 · Severity: medium · CVSS 6.3 · Published 2026-08-31

Executive brief

Doccano is an open-source annotation tool used by machine learning teams to label training data. A flaw in the Project Example Detail endpoint allows attackers to bypass access controls and view or modify project examples they should not have permission to access, potentially compromising the integrity and confidentiality of sensitive training datasets.

Technical details

The vulnerability exists in the ExampleDetail function of the /v1/projects/1/examples/ endpoint in Doccano up to version 1.8.5. The flaw is an improper access control issue that allows remote attackers to bypass authorization checks without authentication. By crafting requests to the Project Example Detail endpoint, an attacker can access or manipulate example documents that they should not have permission to view or modify. No patch has been provided, and the vendor has not responded to early disclosure attempts. A working exploit is publicly available.

Affected products

  • Doccano Doccano up to 1.8.5

Timeline

  • 2026-08-31: disclosed
  • other: Public exploit available; vendor non-responsive to early disclosure

References

Related threats