6.3Medium
CVE-2026-90806
A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.
What this means for your business
- An attacker can use it remotely, over a network, with an ordinary user login, and without anyone at your company clicking anything.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 6.3 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L- CVSS v4
- 5.3
- Weakness
- CWE-862
- Assigned by
- cna@vuldb.com
Dates
- Published
- 2026-09-14
- Last modified
- 2026-09-14
- Sources
- NVD
References
- https://github.com/Django-CRM/Django-CRM/commit/799bb1210238f402c0c4948c8eedb6e61cd0c8d7
- https://github.com/Django-CRM/Django-CRM/issues/745
- https://github.com/Django-CRM/Django-CRM/pull/746
- https://github.com/Django-CRM/Django-CRM/releases/tag/v1.3.0
- https://vuldb.com/cve/CVE-2026-90806
- https://vuldb.com/submit/920489
- https://vuldb.com/vuln/403308
- https://vuldb.com/vuln/403308/cti