Nautobot是Nautobot个人开发者的一个网络自动化平台。 Nautobot 2.4.33之前版本和3.1.2之前版本存在安全漏洞,该漏洞源于通过GenericForeignKey创建或更新对象时,REST API未能强制用户查看权限,导致无法正确验证对其他对象的引用是否有效。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44797 | 8.5 HIGH | Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) |
| CVE-2026-44798 | 7.1 HIGH | Nautobot: GitRepository.current_head field should not be writable through REST API |
| CVE-2026-44796 | 6.5 MEDIUM | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular |
No comments yet