User Permission Flaw in Nautobot Network Automation Platform
CVE-2026-83805

6.4MEDIUM

Key Information:

Vendor

Nautobot

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83805?

Nautobot, a leading Network Automation Platform, has a significant user permission flaw affecting versions 3.0.0 to 3.1.8. The vulnerability arises in the ApprovalWorkflowStageResponse create endpoint, where essential permission checks are inadequately enforced. Specifically, users with minimal extras.add_approvalworkflowstageresponse permission can submit approved responses, bypassing required membership in approver groups, and neglecting restrictions on user responses. This can lead to unauthorized approval of workflows, triggering associated ScheduledJobs without the necessary valid approver oversight. Users are strongly urged to upgrade to version 3.1.8, where this issue has been resolved.

Affected Version(s)

nautobot >= 3.0.0, < 3.1.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.