CVE-2026-82834: A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto
Summary
A security flaw was found in Doccano (an open-source tool for labeling data used in machine learning projects) version 1.8.5 and earlier that allows attackers to bypass access controls (protections that restrict who can do what) through the bulk-delete endpoint. The flaw can be exploited remotely (from anywhere over the internet), the exploit code has been publicly released, and the vendor has not responded to early notifications about the problem.
Vulnerability Details
5.4(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
network
low
low
none
August 31, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82834
First tracked: August 31, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%