{"id":"CVE-2026-85211","title":"Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints","summary":"Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying ar…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-639"],"published":"2026-09-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:53:23.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85211","references":[{"url":"https://github.com/HumanSignal/label-studio","label":"disclosure@vulncheck.com"},{"url":"https://github.com/HumanSignal/label-studio/blob/1.23.0/label_studio/io_storages/proxy_api.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/HumanSignal/label-studio/issues/9924","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/label-studio-through-1.23.0-cross-organization-storage-uri-resolution","label":"disclosure@vulncheck.com"},{"url":"https://github.com/HumanSignal/label-studio/issues/9924","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00238,"epssPercentile":0.15167,"ingestedAt":"2026-09-10T16:57:28.701Z","vendor":"HumanSignal","product":"label-studio","affected":["label-studio <= 1.23.0"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-03T14:31:54.131910Z"},"slug":"CVE-2026-85211","body":"## Overview\n\nLabel Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":210220,"id":"CVE-2026-85211","ts":1790264815672,"field":"exploit_available","old":"false","new":"true"}]}