Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q4c5-2j6f-r476 | Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs |
Tue, 22 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nautobot
Nautobot nautobot |
|
| Vendors & Products |
Nautobot
Nautobot nautobot |
Tue, 22 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and deny actions. A user with only extras.add_approvalworkflowstageresponse can submit approved responses directly, while writable user and state fields permit responses to be attributed to arbitrary users. These forged responses can satisfy min_approvers, approve the workflow, and activate its gated ScheduledJob without a legitimate approver. This issue is fixed in version 3.1.8. | |
| Title | Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T19:47:42.826Z
Reserved: 2026-08-31T23:04:48.172Z
Link: CVE-2026-83805
No data.
Status : Received
Published: 2026-09-22T20:17:09.487
Modified: 2026-09-22T20:17:09.487
Link: CVE-2026-83805
No data.
OpenCVE Enrichment
Updated: 2026-09-22T22:15:07Z
Github GHSA