Django Model Formset Vulnerability in Django Framework
CVE-2026-87975

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-87975?

In Django versions prior to 6.1.2, 6.0.9, and 5.2.18, an issue was identified where the mechanism for processing model forms allowed authenticated users to delete objects outside of their authorized access. Specifically, the save_existing_objects() method in BaseModelFormSet incorrectly utilized the presence of a primary key from submitted data to determine valid objects for deletion. This could lead to unauthorized removal of rows from the database without the necessary permissions, particularly in cases involving inline formsets using fields such as OneToOneField or UUIDs. While designated models using the default AutoField primary key are safe from this issue, it's crucial for users on affected versions to upgrade to the patched releases to ensure robust security.

Affected Version(s)

Django 6.1 < 6.1.2

Django 6.0 < 6.0.9

Django 5.2 < 5.2.18

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seonggwon Yoon
Jacob Walls
Natalia Bidart
Sarah Boyce
.