DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-83805: CVE-2026-83805: Authorization Bypass and Privilege Escalation in Nautobot Approval Workflows

CVE-2026-83805: Authorization Bypass and Privilege Escalation in Nautobot Approval Workflows

Vulnerability ID: CVE-2026-83805
CVSS Score: 6.4
Published: 2026-09-22

An authorization bypass vulnerability exists in Nautobot's REST API endpoints handling approval workflows. Due to an architectural inconsistency, a standalone, generic REST API endpoint for creating approval responses was exposed without propagating the required business-logic validations. This allows low-privileged authenticated users to submit forged, self-approved votes, bypassing approval thresholds and triggering unauthorized server-side automated jobs.

TL;DR

A validation discrepancy between Nautobot controllers allows authenticated low-privileged users to directly POST forged approval responses, bypass group and permission checks, and trigger the execution of privileged automated tasks.


Technical Details

  • CWE ID: CWE-285
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 6.4 (Medium)
  • EPSS Score: 0.00
  • Exploit Status: none
  • KEV Status: Not Listed

Affected Systems

  • Nautobot Network Automation Platform
  • Nautobot: >= 3.0.0, < 3.1.8 (Fixed in: 3.1.8)

Code Analysis

Commit: 8682707

Fix approval workflow stage response endpoint write capabilities and restrict direct routing access

Mitigation Strategies

  • Upgrade Nautobot deployments to version 3.1.8 or higher.
  • Revoke the 'extras.add_approvalworkflowstageresponse' permission from non-administrative users.
  • Implement WAF/API Gateway rules to block modification methods targeting the response endpoints.

Remediation Steps:

  1. Inspect current Nautobot deployment versions and schedule an upgrade to 3.1.8.
  2. Apply database queries to audit for incongruencies between the logged transaction user and the record's user attribute.
  3. Modify default Django user group permissions to restrict approval response addition capabilities.

References


Read the full report for CVE-2026-83805 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)