Django Model Formset Vulnerability in Django Framework
CVE-2026-87975
What is CVE-2026-87975?
In Django versions prior to 6.1.2, 6.0.9, and 5.2.18, an issue was identified where the mechanism for processing model forms allowed authenticated users to delete objects outside of their authorized access. Specifically, the save_existing_objects() method in BaseModelFormSet incorrectly utilized the presence of a primary key from submitted data to determine valid objects for deletion. This could lead to unauthorized removal of rows from the database without the necessary permissions, particularly in cases involving inline formsets using fields such as OneToOneField or UUIDs. While designated models using the default AutoField primary key are safe from this issue, it's crucial for users on affected versions to upgrade to the patched releases to ensure robust security.
Affected Version(s)
Django 6.1 < 6.1.2
Django 6.0 < 6.0.9
Django 5.2 < 5.2.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
