CVE-2026-90806
Last modified
CVE-2026-90806 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update.
Description
A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| DjangoCRM | django-crm | 1.0; 1.1; 1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-90806?
How severe is CVE-2026-90806?
How do I fix CVE-2026-90806?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9080Calling `curl_easy_pause()` within the event-based `CURLMOPT…7.3
- CVE-2026-90801A security flaw has been discovered in GNU Binutils 2.47. Th…5.3
- CVE-2026-90802A weakness has been identified in GNU Binutils 2.47. Affecte…4.4
- CVE-2026-90803A security vulnerability has been detected in GNU Binutils 2…5.3
- CVE-2026-90804A vulnerability was detected in GNU Binutils 2.47. Affected …4.8
- CVE-2026-90805A flaw has been found in subhajitkhan online-clinic-manageme…7.3
- CVE-2026-90807A vulnerability was found in nanocoai NanoClaw up to 2.1.17.…6.3
- CVE-2026-90808A vulnerability was determined in HKUDS nanobot up to 0.2.1.…6.3
- CVE-2026-90809A vulnerability was identified in HKUDS nanobot up to 0.2.1.…7.3
- CVE-2026-9081IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.1…7.1
- CVE-2026-90810A security flaw has been discovered in cosmicstack-labs merc…6.3
- CVE-2026-90811A weakness has been identified in cosmicstack-labs mercury-a…3.3
Are you affected by CVE-2026-90806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
