CVE-2026-44798

Published: Mag 28, 2026 Last Modified: Mag 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: high

Description

AI Translation Available

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local clone(s) of the relevant repository to checkout a commit other than the latest commit on the specified branch (resulting in misleading state), or potentially to be unable to make use of the repository at all (until manually remediated) due to the current_head pointing to a nonexistent commit hash or malformed value. This vulnerability is fixed in 2.4.33 and 3.1.2.

471

Modification of Assumed-Immutable Data (MAID)

Draft
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Modify Application Data Unexpected State
Applicable Platforms
Technologies: Not Technology-Specific, Web Based
View CWE Details
749

Exposed Dangerous Method or Function

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Read Application Data Modify Application Data Execute Unauthorized Code Or Commands Other
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Nautobot by Networktocode

Version Range Affected
To 2.4.33 (exclusive)
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Nautobot by Networktocode

Version Range Affected
From 3.0.0 (inclusive)
To 3.1.2 (exclusive)
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/nautobot/nautobot/commit/9deddfc91ad9260ad17b5e20084e9e2d15b…
https://github.com/nautobot/nautobot/commit/c46f97040b2bde4320be36b23577f19a8bc…
https://github.com/nautobot/nautobot/releases/tag/v2.4.33
https://github.com/nautobot/nautobot/releases/tag/v3.1.2
https://github.com/nautobot/nautobot/security/advisories/GHSA-p3hx-pwf3-j8wr