CVE-2026-4292Disclosure(djangoproject / django)

LOWCVSS 2.7 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch djangoproject django systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
django

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-07: 3Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 304-07
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    5 CVEs fixed in Django https://www.openwall.com/lists/oss-security/2026/04/07/10 CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable + next tweet

    Post summary

    The tweet announces that five Django CVEs have been fixed, providing concise technical descriptions for three of them, but offers no exploit or PoC details.

    10050638
    4.6K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-4292 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new … https://www.cve.org/CVERecord?id=CVE-2026-4292 ----- Traducción: CVE-2026-4292 Se d… http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-4292, lists affected Django versions, and notes a flaw involving ModelAdmin.list_editable, but it does not disclose a PoC, exploit code, or patch.

    0000026
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4292 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new … https://www.cve.org/CVERecord?id=CVE-2026-4292

    Post summary

    CVE-2026-4292 is a discovered flaw in specific application versions where admin changelist forms using `ModelAdmin.list_editable` incorrectly allow new entries; no exploit evidence, patch, or PoC is referenced.

    00000284
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdjangoprojectdjango---

Explore more