CVE-2026-87975
Last modified
CVE-2026-87975 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instance belonged to the formset's limiting queryset. An object outside that queryset is represented by a newly constructed instance whose primary key can still be populated from submitted data when the model's primary key is a field accepted by the form, such as a `OneToOneField` or parent link used as the primary key of an inline formset's model, or a natural or UUID primary key included in the form's fields.
Description
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on a submitted form's instance as evidence that the instance belonged to the formset's limiting queryset. An object outside that queryset is represented by a newly constructed instance whose primary key can still be populated from submitted data when the model's primary key is a field accepted by the form, such as a `OneToOneField` or parent link used as the primary key of an inline formset's model, or a natural or UUID primary key included in the form's fields. This allows an authenticated user permitted to submit such a formset to delete rows outside the limiting queryset, without any permission on the targeted object, via forged management-form data marking an out-of-queryset object for deletion. Models using the default AutoField primary key are not affected. Earlier, unsupported Django series (such as 5.1.x, 5.0.x, and 4.2.x) were not evaluated and may also be affected. Django would like to thank Seonggwon Yoon for reporting this issue.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-87975?
How severe is CVE-2026-87975?
How do I fix CVE-2026-87975?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87965The Easy Appointments WordPress plugin before 4.0.2.2 does n…4.8
- CVE-2026-87966The Easy Appointments WordPress plugin before 4.0.2.2 does n…5.3
- CVE-2026-87969An OS command injection vulnerability in the WatchGuard AP d…8.6
- CVE-2026-8797An access control deficiency vulnerability exists in Express…8.5
- CVE-2026-87970The If-So Dynamic Content WordPress plugin before 1.10.2 do…4.7
- CVE-2026-87973The If-So Dynamic Content WordPress plugin before 1.10.2 do…3.1
- CVE-2026-87976Apache NiFi Registry 0.4.0 through 2.11.0 are subject to pat…8.1
- CVE-2026-87978The Paymob for WooCommerce WordPress plugin before 4.1.14 do…5.3
- CVE-2026-87979The Paymob for WooCommerce WordPress plugin before 4.1.14 do…5.3
- CVE-2026-8798In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3…8.7
- CVE-2026-87981The Paymob for WooCommerce WordPress plugin before 4.1.14 do…4.7
- CVE-2026-87983An arbitrary file read vulnerability in Mistral Vibe, introd…9.2
Are you affected by CVE-2026-87975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
