{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-82833",
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "state": "PUBLISHED",
        "assignerShortName": "VulDB",
        "dateReserved": "2026-08-31T07:25:46.766Z",
        "datePublished": "2026-08-31T19:00:08.707Z",
        "dateUpdated": "2026-09-01T13:59:40.148Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
                "shortName": "VulDB",
                "dateUpdated": "2026-08-31T19:00:08.707Z"
            },
            "title": "Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint examples ExampleDetail access control",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "cweId": "CWE-284",
                            "lang": "en",
                            "description": "Improper Access Controls"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "type": "CWE",
                            "cweId": "CWE-266",
                            "lang": "en",
                            "description": "Incorrect Privilege Assignment"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Doccano",
                    "product": "Open Source Annotation Tools for Machine Learning Practitioners",
                    "versions": [
                        {
                            "version": "1.8.0",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.1",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.2",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.3",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.4",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.5",
                            "status": "affected"
                        }
                    ],
                    "cpes": [
                        "cpe:2.3:a:doccano:open_source_annotation_tools_for_machine_learning_practitioners:*:*:*:*:*:*:*:*"
                    ],
                    "modules": [
                        "Project Example Detail Endpoint"
                    ]
                },
                {
                    "vendor": "Doccano",
                    "product": "Auto Labeling Pipeline Module to Annotate a Document Automatically",
                    "versions": [
                        {
                            "version": "1.8.0",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.1",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.2",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.3",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.4",
                            "status": "affected"
                        },
                        {
                            "version": "1.8.5",
                            "status": "affected"
                        }
                    ],
                    "cpes": [
                        "cpe:2.3:a:doccano:auto_labeling_pipeline_module_to_annotate_a_document_automatically:*:*:*:*:*:*:*:*"
                    ],
                    "modules": [
                        "Project Example Detail Endpoint"
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/ of the component Project Example Detail Endpoint. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "version": "4.0",
                        "baseScore": 5.3,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                        "baseSeverity": "MEDIUM"
                    }
                },
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "baseScore": 6.3,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                        "baseSeverity": "MEDIUM"
                    }
                },
                {
                    "cvssV3_0": {
                        "version": "3.0",
                        "baseScore": 6.3,
                        "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                        "baseSeverity": "MEDIUM"
                    }
                },
                {
                    "cvssV2_0": {
                        "version": "2.0",
                        "baseScore": 6.5,
                        "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"
                    }
                }
            ],
            "timeline": [
                {
                    "time": "2026-08-31T00:00:00.000Z",
                    "lang": "en",
                    "value": "Advisory disclosed"
                },
                {
                    "time": "2026-08-31T02:00:00.000Z",
                    "lang": "en",
                    "value": "VulDB entry created"
                },
                {
                    "time": "2026-08-31T09:30:57.000Z",
                    "lang": "en",
                    "value": "VulDB entry last update"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Stephen Lin (VulDB User)",
                    "type": "reporter"
                },
                {
                    "lang": "en",
                    "value": "VulDB CNA Team",
                    "type": "coordinator"
                }
            ],
            "references": [
                {
                    "url": "https://vuldb.com/vuln/397245",
                    "name": "VDB-397245 | Doccano Open Source Annotation Tools for Machine Learning Practitioners Project Example Detail Endpoint examples ExampleDetail access control",
                    "tags": [
                        "vdb-entry",
                        "technical-description"
                    ]
                },
                {
                    "url": "https://vuldb.com/vuln/397245/cti",
                    "name": "VDB-397245 | CTI Indicators (IOB, IOC, TTP, IOA)",
                    "tags": [
                        "signature",
                        "permissions-required"
                    ]
                },
                {
                    "url": "https://vuldb.com/cve/CVE-2026-82833",
                    "name": "CVE-2026-82833 | CVE Analysis and Report",
                    "tags": [
                        "third-party-advisory"
                    ]
                },
                {
                    "url": "https://vuldb.com/submit/876617",
                    "name": "Submit #876617 | doccano v1.8.5 Broken Access Control",
                    "tags": [
                        "third-party-advisory"
                    ]
                },
                {
                    "url": "https://drive.google.com/file/d/1gqrFfbP7dSSp4Pf-4iEoPtNR7WjSZPML/view?usp=drive_link",
                    "tags": [
                        "exploit"
                    ]
                }
            ],
            "x_generator": [
                "VulDB PVTS v202608"
            ]
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-09-01T13:59:01.106518Z",
                                "id": "CVE-2026-82833",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-09-01T13:59:40.148Z"
                }
            }
        ]
    }
}