Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and label_studio/core/permissions.py registers every permission with rules.is_authenticated, so the check is satisfied by any logged-in account and no object-level organization test runs. The sibling task endpoint does constrain its queryset with project__organization set to the requester's active organization, which is the boundary this path omits. Annotation identifiers are sequential integers, so an authenticated user of one organization can enumerate identifiers to read, modify and delete annotations belonging to other organizations on the same instance. The same unscoped queryset appears on AnnotationConvertAPI in the same file. | |
| Title | Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset | |
| First Time appeared |
Humansignal
Humansignal label Studio |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:humansignal:label_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Humansignal
Humansignal label Studio |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:55:39.204Z
Reserved: 2026-08-18T21:04:48.504Z
Link: CVE-2026-76073
No data.
Status : Received
Published: 2026-08-24T18:17:21.410
Modified: 2026-08-24T18:17:21.410
Link: CVE-2026-76073
No data.
OpenCVE Enrichment
Updated: 2026-08-24T20:45:04Z