Improper Authorization in Nautobot - #VU139393

 

Improper Authorization in Nautobot - #VU139393

Published: July 27, 2026


Vulnerability identifier: #VU139393
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper authorization in the REST API depth query parameter handling when traversing related objects through API requests. A remote user can send a crafted API request using the depth parameter to disclose sensitive information.

The issue affects permission enforcement for related objects reached from an initially authorized root object.


Affected software

Nautobot

Remediation

Install security update from vendor's website.

Nautobot - addressed in versions 2.4.38, 3.2.0

External References

Related Security Bulletins