CVE-2026-4277Disclosure(djangoproject / django)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
django

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-07: 3Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 304-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/04/07/10 CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable + next tweet

    Post summary

    The post announces that five Django CVEs have been fixed, providing brief technical descriptions of three of them, confirming that patches are available.

    10050638
    4.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4277 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of fo… https://www.cve.org/CVERecord?id=CVE-2026-4277 ----- Traducción: CVE-2026-4277 Se d… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-4277, detailing the affected product versions and a short vulnerability description, and provides a link to the official CVE record.

    0000027
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4277 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of fo… https://www.cve.org/CVERecord?id=CVE-2026-4277

    Post summary

    Initial disclosure of CVE-2026-4277, highlighting a missing permission validation on inline model instances in specific software versions. No PoC, exploit code, patch, or evidence of active exploitation reported.

    00000165
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more