Improper Authorization in Nautobot - #VU139393
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in the REST API depth query parameter handling when traversing related objects through API requests. A remote user can send a crafted API request using the depth parameter to disclose sensitive information.
The issue affects permission enforcement for related objects reached from an initially authorized root object.