Incorrect authorization in Django - CVE-2026-87975
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete instances outside the limiting queryset or create instances through edit-only formsets.
nThe vulnerability exists due to improper authorization enforcement in Django model formsets when processing submitted data for models whose primary keys can be set through the form. A remote attacker can submit forged POST data to delete instances outside the limiting queryset or create instances through edit-only formsets.
nAffected configurations include a OneToOneField or parent link used as the primary key of an inline formset's model, or a natural or UUID primary key included in the form's fields. Models using the default BigAutoField primary key are not affected.