---
id: CVE-2026-34203
aliases:
  - GHSA-xmpv-j7p2-j873
  - PYSEC-2026-2224
title: >-
  Nautobot: Management of users via REST API does not apply configured password
  validators
summary: >-
  Nautobot: Management of users via REST API does not apply configured password
  validators
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
vendor: nautobot
product: nautobot
ecosystem: pip
affected:
  - nautobot < 2.4.30
  - 'nautobot >= 3.0.0, < 3.0.10'
patched:
  - nautobot 2.4.30
  - nautobot 3.0.10
published: '2026-03-31'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-xmpv-j7p2-j873'
references:
  - url: >-
      https://github.com/nautobot/nautobot/security/advisories/GHSA-xmpv-j7p2-j873
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34203'
  - url: 'https://github.com/nautobot/nautobot/pull/8778'
  - url: 'https://github.com/nautobot/nautobot/pull/8779'
  - url: >-
      https://github.com/nautobot/nautobot/commit/589f7caf54124ad76bc9fcbb7bdcaa25627cd598
  - url: >-
      https://github.com/nautobot/nautobot/commit/d1ef3135aa02fa07de061e8c085f8cce425fe8c9
  - url: 'https://github.com/nautobot/nautobot'
tags:
  - osv
  - pip
epss: 0.00336
epssPercentile: 0.24183
ingestedAt: '2026-07-13T18:58:05.216Z'
---

## Overview

### Impact

In Nautobot versions prior to 2.4.30 or prior to 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's `AUTH_PASSWORD_VALIDATORS` setting (which defaults to an empty list, i.e., no specific rules, but can be configured in Nautobot's `nautobot_config.py` to apply various rules if desired). This can potentially allow for the creation or modification of users to have passwords that are weak or otherwise do not comply with configured standards.

Management of users via the Nautobot admin UI does correctly enforce configured password validation at this time.

### Patches

The issue is resolved in Nautobot versions 2.4.30 and 3.0.10 and later.

- https://github.com/nautobot/nautobot/pull/8778
- https://github.com/nautobot/nautobot/pull/8779

### Workarounds

Review which users have been granted object permissions to create and modify user accounts as well as having access tokens for the REST API, and restrict access as appropriate.

It may be appropriate furthermore to rotate passwords for any user accounts suspected to have been given weak passwords.

### References

- https://docs.djangoproject.com/en/4.2/ref/settings/#std-setting-AUTH_PASSWORD_VALIDATORS
- http://docs.djangoproject.com/en/4.2/topics/auth/passwords/#password-validation

## Affected packages

- `nautobot < 2.4.30`
- `nautobot >= 3.0.0, < 3.0.10`

## Remediation

Upgrade to a patched release:

- `nautobot 2.4.30`
- `nautobot 3.0.10`
