Ad

CVE-2026-34203

MEDIUM CVSS 3.1: 4.3 EPSS 0.03%
Updated Apr 07, 2026
Django
Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions 3.0.0 — 3.0.10
Fixed In 2.4.30
Type CWE-521
Vendor Django
Public PoC No

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards.

This issue has been patched in versions 2.4.30 and 3.0.10.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Networktocode Nautobot
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
2.4.30
Networktocode Nautobot
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
3.0.0 3.0.10