CVE Feed

    Dashboard / CVE / CVE-2026-34203

    CVE-2026-34203

    Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's nautobot_config.py to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards. This issue has been patched in versions 2.4.30 and 3.0.10.

    Published:Mar 31, 2026
    Last Modified:Apr 8, 2026
    EPS:Mar 31, 2026
    EPSS Score:0.0003
    CVSS Score:2.7

    Affected Products

    Vendor
    Nautobot
    Product
    Nautobot
    Vendor
    Networktocode
    Product
    Nautobot

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High