A vulnerability classified as problematic was found in cvat-ai Cvat up to 2.71.x. Affected by this vulnerability is the function RequestViewSet.create of the component Batch Annotation. Such manipulation leads to improper privilege management.

This vulnerability is listed as CVE-2026-73219. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.