PT-2026-6917 · Unknown · Jsbroks Coco Annotator

Nmmorette

·

Published

2026-02-07

·

Updated

2026-02-27

·

CVE-2026-2109

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions jsbroks COCO Annotator versions up to 0.11.1
Description A flaw exists in jsbroks COCO Annotator that allows for improper authorization. This issue is related to the manipulation of the ID argument within an unknown function of the /api/undo/ file in the Delete Category Handler component. The attack can be initiated remotely, and an exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions prior to 0.11.1 should be used.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-2109

Affected Products

Jsbroks Coco Annotator