CVE-2026-83805: Authorization Bypass and Privilege Escalation in Nautobot Approval Workflows
Vulnerability ID: CVE-2026-83805
CVSS Score: 6.4
Published: 2026-09-22
An authorization bypass vulnerability exists in Nautobot's REST API endpoints handling approval workflows. Due to an architectural inconsistency, a standalone, generic REST API endpoint for creating approval responses was exposed without propagating the required business-logic validations. This allows low-privileged authenticated users to submit forged, self-approved votes, bypassing approval thresholds and triggering unauthorized server-side automated jobs.
TL;DR
A validation discrepancy between Nautobot controllers allows authenticated low-privileged users to directly POST forged approval responses, bypass group and permission checks, and trigger the execution of privileged automated tasks.
Technical Details
- CWE ID: CWE-285
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 6.4 (Medium)
- EPSS Score: 0.00
- Exploit Status: none
- KEV Status: Not Listed
Affected Systems
- Nautobot Network Automation Platform
-
Nautobot: >= 3.0.0, < 3.1.8 (Fixed in:
3.1.8)
Code Analysis
Commit: 8682707
Fix approval workflow stage response endpoint write capabilities and restrict direct routing access
Mitigation Strategies
- Upgrade Nautobot deployments to version 3.1.8 or higher.
- Revoke the 'extras.add_approvalworkflowstageresponse' permission from non-administrative users.
- Implement WAF/API Gateway rules to block modification methods targeting the response endpoints.
Remediation Steps:
- Inspect current Nautobot deployment versions and schedule an upgrade to 3.1.8.
- Apply database queries to audit for incongruencies between the logged transaction user and the record's user attribute.
- Modify default Django user group permissions to restrict approval response addition capabilities.
References
- GHSA-q4c5-2j6f-r476 Security Advisory
- Nautobot Fix Commit 8682707
- Nautobot Release v3.1.8 Official Tag
- NVD - CVE-2026-83805
- CVE.org - CVE-2026-83805
Read the full report for CVE-2026-83805 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)