Description
A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/ of the component Project Example Detail Endpoint. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the ExampleDetail endpoint of Doccano allows remote attackers to bypass access controls and retrieve example data without proper authorization. This improper access control provides a path for confidential information exposure and could be combined with other weaknesses to further compromise data integrity or confidentiality. The weakness is tied to CWE-266 (Incorrect Authorization) and CWE-284 (Improper Access Control).

Affected Systems

Doccano Open Source Annotation Tools for Machine Learning Practitioners and its Auto Labeling Pipeline Module to Annotate a Document Automatically are affected when installed in versions up to 1.8.5. The flaw resides in the /v1/projects/1/examples/ route and can be exploited on any instance of the affected product.

Risk and Exploitability

The CVSS score of 5.3 places this vulnerability in the moderate risk range. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, indicating a lower likelihood of widespread exploitation yet still providing a publicly available exploit. Attackers can launch the attack remotely, creating a realistic threat for systems exposed to untrusted networks or lacking strict endpoint controls. Given the moderate severity and the lack of a vendor response, the risk remains notable and should be addressed promptly.

Generated by OpenCVE AI on August 31, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of Doccano that includes the access‑control fix, if a patched release is available.
  • If an upgrade cannot be performed immediately, restrict or disable the /v1/projects/1/examples endpoint using application‑level or network‑level controls to prevent unauthorized access.
  • Enable detailed monitoring of authentication and authorization logs to detect any attempted abuse of the endpoint and respond to potential data exposure incidents.

Generated by OpenCVE AI on August 31, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/ of the component Project Example Detail Endpoint. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint examples ExampleDetail access control
First Time appeared Doccano
Doccano auto Labeling Pipeline Module To Annotate A Document Automatically
Doccano open Source Annotation Tools For Machine Learning Practitioners
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:doccano:auto_labeling_pipeline_module_to_annotate_a_document_automatically:*:*:*:*:*:*:*:*
cpe:2.3:a:doccano:open_source_annotation_tools_for_machine_learning_practitioners:*:*:*:*:*:*:*:*
Vendors & Products Doccano
Doccano auto Labeling Pipeline Module To Annotate A Document Automatically
Doccano open Source Annotation Tools For Machine Learning Practitioners
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Doccano Auto Labeling Pipeline Module To Annotate A Document Automatically Open Source Annotation Tools For Machine Learning Practitioners
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T19:00:08.707Z

Reserved: 2026-08-31T07:25:46.766Z

Link: CVE-2026-82833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-31T20:17:15.337

Modified: 2026-08-31T20:56:08.800

Link: CVE-2026-82833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:20:19Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control