CVE-2026-82833

Summary

A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/ of the component Project Example Detail Endpoint. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.0affected
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.1affected
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.2affected
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.3affected
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.4affected
DoccanoOpen Source Annotation Tools for Machine Learning Practitioners1.8.5affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.0affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.1affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.2affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.3affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.4affected
DoccanoAuto Labeling Pipeline Module to Annotate a Document Automatically1.8.5affected

Weaknesses

  • CWE-284: Improper Access Controls
  • CWE-266: Incorrect Privilege Assignment

References