No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing check_object_permissions call on the parent_id query parameter of the quality reports API endpoint. Attackers can send requests with sequential integer parent_id values and distinguish between existing and non-existing reports via HTTP 500 versus HTTP 404 response differences, disclosing cross-organization report existence without returning report content. | |
| Title | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence | |
| First Time appeared |
Cvat
Cvat cvat |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cvat:cvat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cvat
Cvat cvat |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-30T16:46:37.380Z
Reserved: 2026-06-30T12:32:16.547Z
Link: CVE-2026-58373
Updated: 2026-06-30T16:46:33.438Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T17:30:15Z