Medium severity5.0NVD Advisory· Published Sep 23, 2026· Updated Sep 23, 2026
CVE-2026-71458
CVE-2026-71458
Description
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.