CVE-2026-4277
Essential information
- Published
- 07/04/2026 15:17
- Modified
- 08/04/2026 21:27
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlineModelAdmin`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank N05ec@LZU-DSLab for reporting this issue.
NVD status
- Status
- Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- 6a34fbeb-21d4-45e7-8e0a-62b95bc12c92
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| django / django | cpe:2.3:a:django:django:<6.0.4:*:*:*:*:*:*:* |
| django / django | cpe:2.3:a:django:django:<5.2.13:*:*:*:*:*:*:* |
| django / django | cpe:2.3:a:django:django:<4.2.30:*:*:*:*:*:*:* |
| django / django | cpe:2.3:a:django:django:*:*:*:*:*:*:*:* |