CVE-2026-1207 | Django up to 4.2.27/5.2.10/6.0.1 band index sql injection (Nessus ID 297749 / WID-SEC-2026-0297)
A vulnerability was found in Django up to 4.2.27/5.2.10/6.0.1. It has been classified as critical. This issue affects some unknown processing. The manipulation of the argument band index leads to sql injection.
This vulnerability is referenced as CVE-2026-1207. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.