PT-2026-30869 · Django+3 · Django+3

Jacob Walls

+1

·

Published

2026-04-07

·

Updated

2026-05-13

·

CVE-2026-4277

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Django versions 6.0 through 6.0.3, 5.2 through 5.2.12, and 4.2 through 4.2.29
Description A flaw exists in the permission validation process for inline model instances within GenericInlineModelAdmin when handling forged POST data. This could allow unauthorized access or modification of data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) may also be affected.
Recommendations Update to Django version 6.0.4 or later. Update to Django version 5.2.13 or later. Update to Django version 4.2.30 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BIT-DJANGO-2026-4277
CVE-2026-4277
GHSA-PWJP-CCJC-GHWG
MGASA-2026-0093
OESA-2026-2216
OESA-2026-2217
OESA-2026-2218
OESA-2026-2219
OESA-2026-2220
OPENSUSE-SU-2026:10516-1
OPENSUSE-SU-2026:10517-1
OPENSUSE-SU-2026:10567-1
OPENSUSE-SU-2026:20578-1
PYSEC-2026-52
USN-8154-1
USN-8154-2

Affected Products

Django
Linuxmint
Red Os
Ubuntu