CVE-2026-33126: Python Peewee All Wildcard Auth Bypass

Directly mapping an 'all' parameter to `True` in a database filter can bypass authorization checks. If the application relies on this filter for access control, requesting 'all' will grant access to all records regardless of user permissions. Instead of substituting a blanket `True` clause, resolve 'all' to the specific records the user is authorized to view

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-33126-python-peewee-all-wildcard-auth-bypass --engine opengrep

Description

Directly mapping an 'all' parameter to `True` in a database filter can bypass authorization checks. If the application relies on this filter for access control, requesting 'all' will grant access to all records regardless of user permissions. Instead of substituting a blanket `True` clause, resolve 'all' to the specific records the user is authorized to view