Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a GenericForeignKey, Nautobot's REST API failed to enforce user "view" permissions when determining whether a given reference to another object would be valid. This vulnerability is fixed in 2.4.33 and 3.1.2.
References
| Link | Resource |
|---|---|
| https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b | Patch |
| https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1 | Patch |
| https://github.com/nautobot/nautobot/releases/tag/v2.4.33 | Product Release Notes |
| https://github.com/nautobot/nautobot/releases/tag/v3.1.2 | Product Release Notes |
| https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 May 2026, 13:29
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* | |
| First Time |
Networktocode nautobot
Networktocode |
|
| References | () https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b - Patch | |
| References | () https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1 - Patch | |
| References | () https://github.com/nautobot/nautobot/releases/tag/v2.4.33 - Product, Release Notes | |
| References | () https://github.com/nautobot/nautobot/releases/tag/v3.1.2 - Product, Release Notes | |
| References | () https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x - Patch, Vendor Advisory |
28 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 18:16
Updated : 2026-05-29 13:29
NVD link : CVE-2026-44794
Mitre link : CVE-2026-44794
CVE.ORG link : CVE-2026-44794
JSON object : View
Products Affected
networktocode
- nautobot
CWE
CWE-862
Missing Authorization
