Junglewise Threat Intelligence

CVE-2026-34203: Nautobot weak password requirement in REST API

CVE-2026-34203 · Severity: low · CVSS 3.1 · Published 2026-03-31

Technologies: nautobot (PyPI). Vendors: PyPI.

Executive brief

Nautobot is a platform used by organizations to manage and automate their network infrastructure. A security flaw in its programming interface (API) allows users to be created or updated with weak passwords that bypass the organization's security policies. This could lead to accounts being protected by easily guessable passwords, potentially compromising the security of the network management system.

Technical details

A vulnerability exists in Nautobot's UserSerializer where the REST API fails to invoke Django's validate_password() method. While the administrative web interface correctly enforces AUTH_PASSWORD_VALIDATORS, the API endpoint bypasses these checks. An attacker with high-privileged access (sufficient to create or edit users) could set passwords that do not meet complexity requirements. This issue is rooted in the missing validation call within the UserSerializer.validate() logic. The vulnerability is addressed in versions 2.4.30 and 3.0.10 by explicitly adding the password validation check to the API workflow.

Affected products

  • Network to Code Nautobot < 2.4.30, >= 3.0.0 < 3.0.10

Timeline

  • 2026-03-30: patched: Fix merged into develop and LTM branches.
  • 2026-03-31: advisory: GitHub Security Advisory GHSA-xmpv-j7p2-j873 published.
  • 2026-03-31: disclosed: CVE-2026-34203 published.

References

Related threats