User Permission Flaw in Nautobot Network Automation Platform
CVE-2026-83805
6.4MEDIUM
What is CVE-2026-83805?
Nautobot, a leading Network Automation Platform, has a significant user permission flaw affecting versions 3.0.0 to 3.1.8. The vulnerability arises in the ApprovalWorkflowStageResponse create endpoint, where essential permission checks are inadequately enforced. Specifically, users with minimal extras.add_approvalworkflowstageresponse permission can submit approved responses, bypassing required membership in approver groups, and neglecting restrictions on user responses. This can lead to unauthorized approval of workflows, triggering associated ScheduledJobs without the necessary valid approver oversight. Users are strongly urged to upgrade to version 3.1.8, where this issue has been resolved.
Affected Version(s)
nautobot >= 3.0.0, < 3.1.8
