Improper Authorization in Nautobot - #VU139396

 

Improper Authorization in Nautobot - #VU139396

Published: July 27, 2026


Vulnerability identifier: #VU139396
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper authorization in the GraphQL implementation when traversing related models through GraphQL queries. A remote user can send a crafted GraphQL query to disclose sensitive information.

The issue occurs because object permissions are enforced at the root of the query but not on traversed related models.


Affected software

Nautobot

Remediation

Install security update from vendor's website.

Nautobot - addressed in versions 2.4.38, 3.2.0

External References

Related Security Bulletins