Skip to main content

New research: Apex vs Claude Code Security vs Codex Security on the same codebase.

Vulnerability disclosure

Forged admin forms can create unauthorized model instances

CVE-2026-4292

Affected product
Django
Severity
Low
CVSS
2.7
Weakness
CWE-862
Published

Disclosure summary

CVE-2026-4292 is a low-severity CWE-862 vulnerability in Django. Forged admin forms can create unauthorized model instances. Cantina reproduced the behavior, verified its security impact, and coordinated disclosure with the affected maintainer.

Verification standard

Cantina publishes a disclosure only after reproducing the behavior, validating its security impact, and coordinating remediation with the affected project.