Description
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and label_studio/core/permissions.py registers every permission with rules.is_authenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with project__organization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file.
Published: 2026-08-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access, modification, and deletion of annotations across organization boundaries
Action: Immediate Patch
AI Analysis

Impact

Label Studio fails to restrict the AnnotationAPI to the organization of the requesting user. The endpoint’s queryset is set to all annotations, and the permission checks only enforce that the user is authenticated, not that they belong to the same organization. Consequently, any authenticated user can construct annotation identifiers and gain read, write, or delete capabilities on annotations that belong to other organizations. This vulnerability allows data leakage, integrity compromise, and potential deletion of cross‑organization annotation content.

Affected Systems

HumanSignal Label Studio versions up to and including 1.23.0 are affected. The flaw is present in the annotation detail and AnnotationConvertAPI endpoints, both located in the tasks API module of the 1.23.0 release.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity remote attack surface. Although the EPSS score is currently not available, the vulnerability is not listed in CISA’s KEV catalog. Attackers only need to authenticate to the instance; enumeration of sequential annotation identifiers is trivial, enabling cross‑organization data access. Because no object‑level checks are performed, the exploit requires no additional privileges beyond login credentials, making it highly actionable.

Generated by OpenCVE AI on August 24, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Label Studio to the latest version that contains the annotation scoping fix.
  • If an upgrade is not immediately possible, revoke AnnotationAPI permissions for all users and assign new token scopes that enforce organization membership.
  • Apply the repository patch or modify the AnnotationAPI queryset to filter by the requester's active organization before processing requests.
  • Monitor audit logs for abnormal enumeration patterns or cross‑organization annotation activity to detect potential exploitation.

Generated by OpenCVE AI on August 24, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and label_studio/core/permissions.py registers every permission with rules.is_authenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with project__organization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file.
Title Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset
First Time appeared Humansignal
Humansignal label Studio
Weaknesses CWE-639
CPEs cpe:2.3:a:humansignal:label_studio:*:*:*:*:*:*:*:*
Vendors & Products Humansignal
Humansignal label Studio
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Humansignal Label Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-26T16:13:40.083Z

Reserved: 2026-08-18T21:04:48.504Z

Link: CVE-2026-76073

cve-icon Vulnrichment

Updated: 2026-08-26T15:57:17.331Z

cve-icon NVD

Status : Received

Published: 2026-08-24T18:17:21.410

Modified: 2026-08-26T17:17:13.830

Link: CVE-2026-76073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key