CVE-2026-34406Disclosure(aptrs / aptrs)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and submit crafted permission to escalate their own account (or any other account) to superuser by including "is_superuser": true in the request body. The root cause is that CustomUserSerializer explicitly includes is_superuser in its fields list but omits it from read_only_fields, making it a writable field. The edit_user view performs no additional validation to prevent non-superusers from modifying this field. Once is_superuser is set to true, gaining unrestricted access to all application functionality without requiring re-authentication. This issue has been patched in version 2.0.1.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aptrs

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-01)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
aptrs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2PoC Mentioned / Linked · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3104-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-012
Disclosure1General1
Full discourse3 posts
  • Juan Felipe Oz@PwnedRar_
    Disclosure

    I've been doing research, and i got some new CVEs: CVE-2026-34406 (Critical 9.4) - APTRS CVE-2026-34381 (High 7.5) CVE-2026-34382 (Medium 4.6) https://github.com/APTRS/APTRS/security/advisories/GHSA-gv25-wp4h-9c35 #researching #0days #cibersecurity #hacking #cve

    Post summary

    The user discloses several new CVEs with their CVSS scores and links to a GitHub advisory, but offers no PoC, exploit, or patch information.

    0001061
    116 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34406 APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizatio… https://www.cve.org/CVERecord?id=CVE-2026-34406

    Post summary

    The snippet merely identifies the CVE and points to a CVE record URL, providing no details on exploitation, patching, or technical aspects.

    00010108
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34406: APTRS: Privilege Escalation via ... Mass assignment strikes again - Django serializer exposes `is_superuser` as writable field, instant admin escalation fo... https://zerodaysignal.com/vulnerability/CVE-2026-34406 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-34406, a privilege escalation flaw in Django caused by mass assignment of the `is_superuser` field, and links to a vulnerability page for more details.

    0000076
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaptrsaptrs-python-

Explore more