Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 30 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parent_id values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content. | |
| Title | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence | |
| First Time appeared |
Cvat
Cvat cvat |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cvat:cvat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cvat
Cvat cvat |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T16:46:37.380Z
Reserved: 2026-06-30T12:32:16.547Z
Link: CVE-2026-58373
Updated: 2026-06-30T16:46:33.438Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T17:30:15Z