Stored Cross-Site Scripting in Nautobot Network Automation Platform
CVE-2026-83801

5.4MEDIUM

Key Information:

Vendor

Nautobot

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83801?

The Nautobot Network Automation Platform is vulnerable to stored Cross-Site Scripting (XSS) due to improper handling of user input in relationship descriptions and module family names. Malicious users with certain permissions can inject HTML or JavaScript code, which is then executed in the browsers of authenticated users, including administrators and superusers. This allows attackers to hijack sessions, steal tokens, and potentially escalate privileges. The issue has been addressed in Nautobot versions 2.4.37 and 3.1.8, which users are advised to upgrade to in order to mitigate this risk.

Affected Version(s)

nautobot < 2.4.37 < 2.4.37

nautobot >= 3.0.0, < 3.1.8 < 3.0.0, 3.1.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.