Executive brief
Django is a popular web framework used to build and manage websites. A security flaw in its administrative interface could allow a user with limited access to add new data records they are not authorized to create. This occurs because the system fails to properly check permissions when receiving specifically crafted web requests, potentially leading to unauthorized data entry.
Technical details
A vulnerability classified as Missing Authorization (CWE-862) exists in Django's GenericInlineModelAdmin. The component fails to validate 'add' permissions when processing forged POST data for inline model instances. An attacker with low-level administrative privileges can exploit this by submitting crafted requests to create model instances they should not have permission to add. The issue affects Django versions 6.0.x, 5.2.x, and 4.2.x, and has been addressed in versions 6.0.4, 5.2.13, and 4.2.30.
Affected products
- Django Software Foundation Django >= 6.0, < 6.0.4
- Django Software Foundation Django >= 5.2, < 5.2.13
- Django Software Foundation Django >= 4.2, < 4.2.30
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory
- 2026-04-07: patched