Weak Password Validation in Nautobot Network Automation Platform
CVE-2026-34203

2.7LOW

Key Information:

Vendor

Nautobot

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34203?

Nautobot, a leading network automation platform, has a vulnerability in its REST API related to user creation and editing. Prior to updates in versions 2.4.30 and 3.0.10, the platform did not properly enforce password validation as per Django's AUTH_PASSWORD_VALIDATORS settings. This oversight allowed for the creation or modification of user accounts that could potentially utilize weak passwords that fail to meet desired security standards. Administrators are encouraged to update their Nautobot installations to ensure compliance with best password practices and enhance overall security.

Affected Version(s)

nautobot < 2.4.30 < 2.4.30

nautobot >= 3.0.0, < 3.0.10 < 3.0.0, 3.0.10

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.