An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new
instances to be created via forged `POST` data.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Cantina for reporting this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue. | |
| Title | Privilege abuse in ModelAdmin.list_editable | |
| Weaknesses | CWE-862 | |
| References |
|
Status: PUBLISHED
Assigner: DSF
Published:
Updated: 2026-04-07T15:12:56.065Z
Reserved: 2026-03-16T16:58:02.592Z
Link: CVE-2026-4292
Updated: 2026-04-07T15:12:42.904Z
Status : Received
Published: 2026-04-07T15:17:46.650
Modified: 2026-04-07T16:16:30.220
Link: CVE-2026-4292
No data.
OpenCVE Enrichment
No data.