CVE-2026-4277 is a critical vulnerability affecting Django's GenericInlineModelAdmin component across multiple versions (6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30). The flaw involves insufficient validation of add permissions on inline model instances when forged POST data is submitted, potentially allowing unauthorized permission escalation. Unsupported Django series including 5.0.x, 4.1.x, and 3.2.x may also be vulnerable. The vulnerability carries a CVSS score of 9.8 (CRITICAL) with a network-based attack vector requiring no privileges or user interaction, meaning any unauthenticated remote actor can exploit it. The attack has low complexity and impacts all three security dimensions: confidentiality, integrity, and availability can all be compromised. Current exploitation status indicates minimal active threat activity. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains on an inactive hot list, with an EPSS score of 0.0002 suggesting low current exploitation likelihood. However, given the critical severity rating and publicly disclosed nature, organizations should prioritize patching to mitigate potential future exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2, < 4.2.30CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2.13CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.4CPE match | cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.