Description
A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A vulnerability was discovered in DjangoCRM django‑crm, affecting the BulkUpdateCasesView in bulk_views.py. The flaw allows an attacker to invoke a bulk case update operation without proper authorization, enabling unauthorized modification of case data. This issue is a manifestation of Missing Authorization and Authorization Bypass weaknesses, permitting changes to multiple cases at once.

Affected Systems

The flaw exists in DjangoCRM django‑crm versions 1.2 and earlier. Upgrading to version 1.3.0, which includes the patch identified by commit 799bb1210238f402c0c4948c8eedb6e61cd0c8d7, removes the vulnerability.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating moderate severity. No EPSS data is available and it is not listed in the CISA KEV catalogue, suggesting it is not actively exploited in the wild. The description states that the attack is possible to be carried out remotely; the likely attack vector is via the bulk update endpoint, which an unauthenticated or improperly authorized user could reach if upstream access controls are insufficient.

Generated by OpenCVE AI on September 15, 2026 at 07:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest release, DjangoCRM django‑crm v1.3.0 or later, applying patch commit 799bb1210238f402c0c4948c8eedb6e61cd0c8d7.
  • Restrict access to the bulk case update interface so that only users with appropriate permissions can reach it, ensuring the URL is not publicly exposed.
  • Review any custom or legacy bulk update workflows and disable or patch those that may bypass the updated authorization controls.

Generated by OpenCVE AI on September 15, 2026 at 07:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to version 1.3.0 is able to resolve this issue. The identifier of the patch is 799bb1210238f402c0c4948c8eedb6e61cd0c8d7. You should upgrade the affected component.
Title DjangoCRM django-crm Bulk Case Update bulk_views.py BulkUpdateCasesView authorization
First Time appeared Djangocrm
Djangocrm django-crm
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:djangocrm:django-crm:*:*:*:*:*:*:*:*
Vendors & Products Djangocrm
Djangocrm django-crm
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Djangocrm Django-crm
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:57:14.310Z

Reserved: 2026-09-13T15:45:40.850Z

Link: CVE-2026-90806

cve-icon Vulnrichment

Updated: 2026-09-14T17:56:49.217Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:27.950

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T08:00:16Z

Weaknesses