CVE-2026-82833: A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Label
Summary
A security flaw was found in Doccano, an open-source tool used to label data for machine learning projects, affecting versions up to 1.8.5. The vulnerability is in a specific function that handles project examples and allows attackers to bypass access controls (restrictions on who can view or modify data), and the attack can be done remotely over the internet. The vendor was notified but did not respond, and working exploits are already publicly available.
Vulnerability Details
6.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
network
low
low
none
August 31, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82833
First tracked: August 31, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%