CVE-2026-33469: Orm Auth Bypass With All Keyword

The code assigns `True` to an ORM query clause when a parameter equals "all", effectively bypassing record-specific filtering. If not properly guarded by an authorization check verifying the user has global read access, this allows attackers to access restricted records. Validate user permissions or filter against an explicit list of allowed records instead

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-33469-orm-auth-bypass-with-all-keyword --engine opengrep

Description

The code assigns `True` to an ORM query clause when a parameter equals "all", effectively bypassing record-specific filtering. If not properly guarded by an authorization check verifying the user has global read access, this allows attackers to access restricted records. Validate user permissions or filter against an explicit list of allowed records instead