← Back

CVE-2026-4277

nvd nist
Published: Apr 7, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.

Affected (3)

1 product
Django
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
From 4.2 to 4.2.30
From 5.2 to 5.2.13
From 6.0 to 6.0.4

References (3)

Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
PatchVendor Advisory
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
Release Notes
Source: 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
PatchVendor Advisory

Timeline

No history available yet.