CVE-2026-44794
medium
CVSS v3
—
CVSS v2
—
VIR risk
5.5
Description
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- https://github.com/nautobot/nautobot/security/advisories/GHSA-wpxj-44w3-2j6x
- https://github.com/nautobot/nautobot/commit/36cde7148a207234de6212ec074f321dbc9d1b5b
- https://github.com/nautobot/nautobot/commit/9918bdb9bcf1eb42cda72c344f420a64ef7665f1
- https://github.com/nautobot/nautobot
- https://github.com/nautobot/nautobot/releases/tag/v2.4.33
- https://github.com/nautobot/nautobot/releases/tag/v3.1.2
- https://github.com/advisories/GHSA-wpxj-44w3-2j6x
Verify integrity in audit chain (admin only). AS-IS.