Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a GenericForeignKey, Nautobot's REST API failed to enforce user "view" permissions when determining whether a given reference to another object would be valid. This vulnerability is fixed in 2.4.33 and 3.1.2.
References
| Link | Resource |
|---|---|
| https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b | Patch |
| https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1 | Patch |
| https://github.com/nautobot/nautobot/releases/tag/v2.4.33 | Product Release Notes |
| https://github.com/nautobot/nautobot/releases/tag/v3.1.2 | Product Release Notes |
| https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-28 18:16
Updated : 2026-06-17 10:51
NVD link : CVE-2026-44794
Mitre link : CVE-2026-44794
CVE.ORG link : CVE-2026-44794
JSON object : View
Products Affected
networktocode
- nautobot
CWE
CWE-862
Missing Authorization
