CVE-2026-34203
Last modified
CVE-2026-34203 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards. This issue has been patched in versions 2.4.30 and 3.0.10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Networktocode | Nautobot | < 2.4.30 |
| Networktocode | Nautobot | >= 3.0.0, < 3.0.10 |
References
- https://github.com/nautobot/nautobot/pull/8778Issue Tracking, Patch
- https://github.com/nautobot/nautobot/pull/8779Issue Tracking, Patch
- https://github.com/nautobot/nautobot/security/advisories/GHSA-xmpv-j7p2-j873Mitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34203?
How severe is CVE-2026-34203?
How do I fix CVE-2026-34203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34195Software installed and run as a non-privileged user may cond…8.8
- CVE-2026-34196Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-34197Improper Input Validation, Improper Control of Generation of…8.8
- CVE-2026-34198Coolify is an open-source and self-hostable tool for managin…5.3
- CVE-2026-34200Nhost is an open source Firebase alternative with GraphQL. P…7.5
- CVE-2026-34202ZEBRA is a Zcash node written entirely in Rust. Prior to zeb…7.5
- CVE-2026-34204MinIO is a high-performance object storage system. Prior to …7.1
- CVE-2026-34205Home Assistant is open source home automation software that …9.6
- CVE-2026-34206Captcha Protect is a Traefik middleware to add an anti-bot c…6.1
- CVE-2026-34207TypeBot is a chatbot builder tool. In versions prior to 3.16…7.6
- CVE-2026-34208SandboxJS is a JavaScript sandboxing library. Prior to 0.8.3…10
- CVE-2026-34209mppx is a TypeScript interface for machine payments protocol…7.5
Are you affected by CVE-2026-34203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
