CVE-2026-2109
Last modified
CVE-2026-2109 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jsbroks | Coco Annotator | <= 0.11.1 |
References
- https://vuldb.com/?ctiid.344685Permissions Required, VDB Entry
- https://vuldb.com/?id.344685Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.745579Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2109?
How severe is CVE-2026-2109?
How do I fix CVE-2026-2109?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-21084Improper access control in SmartThings prior to version 1.8.…6.9
- CVE-2026-21085Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2…6.7
- CVE-2026-21086Improper authorization in ProxyHandler prior to SMR Aug-2026…4.8
- CVE-2026-21087Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Rel…7.8
- CVE-2026-21088Improper input validation in loading a subtitle frame in lib…7.8
- CVE-2026-21089Improper input validation in removing style tag in libsubext…7.8
- CVE-2026-21090Out-of-bounds write in libsaviextractor.so prior to SMR Sep-…7.8
- CVE-2026-21091Out-of-bounds write in libcodec2secevrcdec.so prior to SMR S…7.8
- CVE-2026-21092Path traversal in ImsService prior to SMR Sep-2026 Release 1…5.3
- CVE-2026-21093Stack-based buffer overflow in PROCA trustlet prior to SMR S…6.7
- CVE-2026-21094Improper input validation in wpa_supplicant prior to SMR Sep…8.8
- CVE-2026-21095Heap-based buffer overflow in DNG decoder of libimagecodec.q…9.8
Are you affected by CVE-2026-2109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
