Threats Tagged 'cve-2026-87975'
View all threats tagged with 'cve-2026-87975'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-87975'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in Django versions 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18 allows an authenticated user with permission to submit a formset to delete database rows outside the formset's limiting queryset. This occurs because the save_existing_objects() method incorrectly trusts the presence of a primary key in submitted form data as proof that the object belongs to the queryset, enabling deletion of unauthorized objects when certain primary key types are used. Models with default AutoField primary keys are not affected. Join the discussion | GCVE Database | 10/06/2026, 15:32:01 UTC Added: 10/06/2026, 16:35:59 UTC |
0 CVE-2026-87975 is an authorization bypass vulnerability in Django affecting versions 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. The issue arises in django.forms.models.BaseModelFormSet.save_existing_objects(), which incorrectly trusts the presence of a primary key on a submitted form's instance as proof that the instance belongs to the formset's limiting queryset. This flaw allows an authenticated user with permission to submit such a formset to delete objects outside the intended queryset by submitting forged management-form data. Models using the default AutoField primary key are not affected. The vulnerability has a medium severity with a CVSS score of 4.3. Join the discussion | CVE Database V5 | 10/06/2026, 13:35:59 UTC Added: 10/06/2026, 13:49:10 UTC |
Showing 1 to 2 of 2 results