CVE-2026-44794

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a GenericForeignKey, Nautobot's REST API failed to enforce user "view" permissions when determining whether a given reference to another object would be valid. This vulnerability is fixed in 2.4.33 and 3.1.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-28 18:16

Updated : 2026-06-17 10:51


NVD link : CVE-2026-44794

Mitre link : CVE-2026-44794

CVE.ORG link : CVE-2026-44794


JSON object : View

Products Affected

networktocode

  • nautobot
CWE
CWE-862

Missing Authorization