CVE-2026-33469: Orm Auth Bypass With All Keywordcve-2026-33469-orm-auth-bypass-with-all-keyword
The code assigns `True` to an ORM query clause when a parameter equals "all", effectively bypassing record-specific filtering. If not properly guarded by an authorization check verifying the user has global read access, this allows attackers to access restricted records. Validate user permissions or filter against an explicit list of allowed records instead