PT-2026-30869 · Djangoproject · Django

Jacob Walls

+1

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-4277

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged POST data in GenericInlineModelAdmin. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4277

Affected Products

Django