CVE-2026-34203Disclosure(networktocode / nautobot)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards. This issue has been patched in versions 2.4.30 and 3.0.10.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-521

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nautobot

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
nautobot

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-01: 2Technical Details · 2026-04-01: 204-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34203 Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply … https://www.cve.org/CVERecord?id=CVE-2026-34203 ----- Traducción: CVE-2026-34203 Nau… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑34203 for Nautobot, noting an API bug that prevents user creation/editing in older releases, but provides no PoC or exploit details.

    0000021
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34203 Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply … https://www.cve.org/CVERecord?id=CVE-2026-34203

    Post summary

    The post announces a new CVE affecting Nautobot's REST API for user creation and editing, offering a brief functional description without presenting PoC or exploitation details.

    00000173
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnetworktocodenautobot---

Explore more