CVE-2026-44794

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a GenericForeignKey, Nautobot's REST API failed to enforce user "view" permissions when determining whether a given reference to another object would be valid. This vulnerability is fixed in 2.4.33 and 3.1.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*

History

29 May 2026, 13:29

Type Values Removed Values Added
CPE cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
First Time Networktocode nautobot
Networktocode
References () https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b - () https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b - Patch
References () https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1 - () https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1 - Patch
References () https://github.com/nautobot/nautobot/releases/tag/v2.4.33 - () https://github.com/nautobot/nautobot/releases/tag/v2.4.33 - Product, Release Notes
References () https://github.com/nautobot/nautobot/releases/tag/v3.1.2 - () https://github.com/nautobot/nautobot/releases/tag/v3.1.2 - Product, Release Notes
References () https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x - () https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x - Patch, Vendor Advisory

28 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 18:16

Updated : 2026-05-29 13:29


NVD link : CVE-2026-44794

Mitre link : CVE-2026-44794

CVE.ORG link : CVE-2026-44794


JSON object : View

Products Affected

networktocode

  • nautobot
CWE
CWE-862

Missing Authorization