๐Ÿ” CVE Alert

CVE-2026-83805

MEDIUM 6.4

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8.

CWE CWE-285 CWE-639
Vendor nautobot
Product nautobot
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for nautobot nautobot

Be the first to know when new medium vulnerabilities affecting nautobot nautobot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

nautobot / nautobot
>= 3.0.0, < 3.1.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nautobot/nautobot/security/advisories/GHSA-q4c5-2j6f-r476 github.com: https://github.com/nautobot/nautobot/commit/8682707d0391cbfd7694e3276127b78dc9cf29d8 github.com: https://github.com/nautobot/nautobot/releases/tag/v3.1.8