By vendor
Cvat vulnerabilities
Known CVEs affecting Cvat products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-58373MEDIUM 4.3
CVAT, a computer vision annotation tool, has an authorization flaw that lets authenticated users discover which quality reports exist in other organizations. An attacker with valid login credentials can probe the quality reports API by trying different report IDs and observing whether the system returns a 'not found' or 'server error' response—leaking the fact that a report exists without revealing its contents. This affects CVAT versions before 2.69.0.