CVE-2026-2109 | jsbroks COCO Annotator up to 0.11.1 Delete Category /api/undo/ ID improper authorization (EUVD-2026-5718)
A vulnerability was found in jsbroks COCO Annotator up to 0.11.1 and classified as problematic. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization.
This vulnerability is traded as CVE-2026-2109. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.