Skip to main content

Threats Tagged 'cve-2026-87975'

View all threats tagged with 'cve-2026-87975'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-87975

Threats Tagged 'cve-2026-87975'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in Django versions 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18 allows an authenticated user with permission to submit a formset to delete database rows outside the formset's limiting queryset. This occurs because the save_existing_objects() method incorrectly trusts the presence of a primary key in submitted form data as proof that the object belongs to the queryset, enabling deletion of unauthorized objects when certain primary key types are used. Models with default AutoField primary keys are not affected.

Join the discussion

CVE-2026-87975 is an authorization bypass vulnerability in Django affecting versions 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. The issue arises in django.forms.models.BaseModelFormSet.save_existing_objects(), which incorrectly trusts the presence of a primary key on a submitted form's instance as proof that the instance belongs to the formset's limiting queryset. This flaw allows an authenticated user with permission to submit such a formset to delete objects outside the intended queryset by submitting forged management-form data. Models using the default AutoField primary key are not affected. The vulnerability has a medium severity with a CVSS score of 4.3.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-87975
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses