Description
A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the component Bulk-Delete Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the component Bulk-Delete Endpoint. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-Delete Endpoint category-types LabelList access control
First Time appeared Doccano
Doccano auto Labeling Pipeline Module To Annotate A Document Automatically
Doccano open Source Annotation Tools For Machine Learning Practitioners
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:doccano:auto_labeling_pipeline_module_to_annotate_a_document_automatically:*:*:*:*:*:*:*:*
cpe:2.3:a:doccano:open_source_annotation_tools_for_machine_learning_practitioners:*:*:*:*:*:*:*:*
Vendors & Products Doccano
Doccano auto Labeling Pipeline Module To Annotate A Document Automatically
Doccano open Source Annotation Tools For Machine Learning Practitioners
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Doccano Auto Labeling Pipeline Module To Annotate A Document Automatically Open Source Annotation Tools For Machine Learning Practitioners
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T19:15:08.323Z

Reserved: 2026-08-31T07:25:51.029Z

Link: CVE-2026-82834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T20:17:15.510

Modified: 2026-08-31T20:17:15.510

Link: CVE-2026-82834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control