Search
Find a vulnerability
Search criteria
6 vulnerabilities found for netbox by netbox-community
CVE-2026-86176 (GCVE-0-2026-86176)
Vulnerability from nvd – Published: 2026-09-05 11:01 – Updated: 2026-09-24 14:21
VLAI
EPSS
VEX
Title
NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs
Summary
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:06 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/geo-chen/oss/blob/main/netbox.… | third-party-advisoryexploit |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox | product |
| https://www.vulncheck.com/advisories/netbox-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
0 , ≤ 4.7.0
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-09-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86176",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:06:47.622473Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:23:11.327Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/netbox-community/netbox",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users\u0027 private records through unscoped querysets, disclosing which users watch or bookmark which objects."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:16.154Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Advisory",
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-1-cross-user-disclosure-of-private-notifications-subscriptions-and-bookmarks-via-rest-api-and-graphql-missing-per-user-scoping"
},
{
"name": "Bookmark, Notification and Subscription viewsets",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/extras/api/views.py#L153-L178"
},
{
"name": "EXEMPT_EXCLUDE_MODELS",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/netbox/settings.py#L667-L673"
},
{
"tags": [
"product"
],
"url": "https://github.com/netbox-community/netbox"
},
{
"name": "VulnCheck Advisory: NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-through-4.7.0-information-disclosure-via-rest-and-graphql-apis"
}
],
"title": "NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-86176",
"datePublished": "2026-09-05T11:01:27.414Z",
"dateReserved": "2026-09-05T10:40:40.966Z",
"dateUpdated": "2026-09-24T14:21:16.154Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86175 (GCVE-0-2026-86175)
Vulnerability from nvd – Published: 2026-09-05 11:01 – Updated: 2026-09-24 14:21
VLAI
EPSS
VEX
Title
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
Summary
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-08 13:13 UTC
CWE
- CWE-522 - Insufficiently Protected Credentials
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/geo-chen/oss/blob/main/netbox.… | third-party-advisoryexploit |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/issues/12625 | issue-tracking |
| https://github.com/netbox-community/netbox | product |
| https://www.vulncheck.com/advisories/netbox-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
0 , ≤ 4.7.0
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-09-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86175",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T13:13:05.582427Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T13:13:33.718Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/netbox-community/netbox",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-522",
"description": "Insufficiently Protected Credentials",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:15.185Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Advisory",
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-2-netbox-data-source-backend-credentials-git-password--s3-secret-key-returned-in-plaintext-via-rest-api-and-graphql-to-users-with-only-view-permission-incomplete-fix-of-12625"
},
{
"name": "DataSourceSerializer Meta.fields",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/api/serializers_/data.py#L26-L32"
},
{
"name": "DataSourceType GraphQL fields",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/graphql/types.py#L30-L38"
},
{
"name": "GitBackend sensitive_parameters",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/data_backends.py#L80"
},
{
"name": "GitHub Issue #12625",
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/issues/12625"
},
{
"tags": [
"product"
],
"url": "https://github.com/netbox-community/netbox"
},
{
"name": "VulnCheck Advisory: NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-through-4.7.0-credential-disclosure-via-rest-and-graphql-apis"
}
],
"title": "NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-86175",
"datePublished": "2026-09-05T11:01:26.738Z",
"dateReserved": "2026-09-05T10:40:36.294Z",
"dateUpdated": "2026-09-24T14:21:15.185Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-29514 (GCVE-0-2026-29514)
Vulnerability from nvd – Published: 2026-05-04 16:05 – Updated: 2026-07-14 18:39 X_Open Source
VLAI
EPSS
VEX
Title
NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
Summary
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox's call interception mechanism, achieving remote code execution as the NetBox service user.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-05-04 16:59 UTC
CWE
- CWE-183 - Permissive List of Allowed Inputs
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://chocapikk.com/posts/2026/netbox-export-te… | technical-descriptionexploit |
| https://github.com/netbox-community/netbox/issues/22079 | issue-tracking |
| https://github.com/netbox-community/netbox/pull/22078 | issue-tracking |
| https://github.com/netbox-community/netbox/pull/22170 | issue-tracking |
| https://github.com/netbox-community/netbox/releas… | release-notes |
| https://github.com/netbox-community/netbox/commit… | patch |
| https://www.vulncheck.com/advisories/netbox-rce-v… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
4.3.5 , ≤ 4.5.4
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-05-01 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-29514",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-04T16:59:06.882812Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-04T16:59:25.855Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.5.4",
"status": "affected",
"version": "4.3.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.5.4",
"versionStartIncluding": "4.3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Valentin Lobstein (Chocapikk)"
}
],
"datePublic": "2026-05-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox\u0027s call interception mechanism, achieving remote code execution as the NetBox service user."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-183",
"description": "Permissive List of Allowed Inputs",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T18:39:54.647Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"technical-description",
"exploit"
],
"url": "https://chocapikk.com/posts/2026/netbox-export-template-rce/"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/issues/22079"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/pull/22078"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/pull/22170"
},
{
"tags": [
"release-notes"
],
"url": "https://github.com/netbox-community/netbox/releases/tag/v4.6.1"
},
{
"tags": [
"patch"
],
"url": "https://github.com/netbox-community/netbox/commit/d124c5fe86e12aad61285133c0caf16adcda8f2e"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-rce-via-rendertemplatemixin"
}
],
"source": {
"discovery": "EXTERNAL"
},
"tags": [
"x_open-source"
],
"title": "NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-29514",
"datePublished": "2026-05-04T16:05:33.894Z",
"dateReserved": "2026-03-04T15:39:26.872Z",
"dateUpdated": "2026-07-14T18:39:54.647Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86176 (GCVE-0-2026-86176)
Vulnerability from cvelistv5 – Published: 2026-09-05 11:01 – Updated: 2026-09-24 14:21
VLAI
EPSS
VEX
Title
NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs
Summary
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:06 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/geo-chen/oss/blob/main/netbox.… | third-party-advisoryexploit |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox | product |
| https://www.vulncheck.com/advisories/netbox-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
0 , ≤ 4.7.0
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-09-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86176",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:06:47.622473Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:23:11.327Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/netbox-community/netbox",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users\u0027 private records through unscoped querysets, disclosing which users watch or bookmark which objects."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:16.154Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Advisory",
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-1-cross-user-disclosure-of-private-notifications-subscriptions-and-bookmarks-via-rest-api-and-graphql-missing-per-user-scoping"
},
{
"name": "Bookmark, Notification and Subscription viewsets",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/extras/api/views.py#L153-L178"
},
{
"name": "EXEMPT_EXCLUDE_MODELS",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/netbox/settings.py#L667-L673"
},
{
"tags": [
"product"
],
"url": "https://github.com/netbox-community/netbox"
},
{
"name": "VulnCheck Advisory: NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-through-4.7.0-information-disclosure-via-rest-and-graphql-apis"
}
],
"title": "NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-86176",
"datePublished": "2026-09-05T11:01:27.414Z",
"dateReserved": "2026-09-05T10:40:40.966Z",
"dateUpdated": "2026-09-24T14:21:16.154Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86175 (GCVE-0-2026-86175)
Vulnerability from cvelistv5 – Published: 2026-09-05 11:01 – Updated: 2026-09-24 14:21
VLAI
EPSS
VEX
Title
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
Summary
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-08 13:13 UTC
CWE
- CWE-522 - Insufficiently Protected Credentials
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/geo-chen/oss/blob/main/netbox.… | third-party-advisoryexploit |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/blob/v… | technical-description |
| https://github.com/netbox-community/netbox/issues/12625 | issue-tracking |
| https://github.com/netbox-community/netbox | product |
| https://www.vulncheck.com/advisories/netbox-throu… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
0 , ≤ 4.7.0
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-09-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86175",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T13:13:05.582427Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T13:13:33.718Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/netbox-community/netbox",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-09-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-522",
"description": "Insufficiently Protected Credentials",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:21:15.185Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Advisory",
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-2-netbox-data-source-backend-credentials-git-password--s3-secret-key-returned-in-plaintext-via-rest-api-and-graphql-to-users-with-only-view-permission-incomplete-fix-of-12625"
},
{
"name": "DataSourceSerializer Meta.fields",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/api/serializers_/data.py#L26-L32"
},
{
"name": "DataSourceType GraphQL fields",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/graphql/types.py#L30-L38"
},
{
"name": "GitBackend sensitive_parameters",
"tags": [
"technical-description"
],
"url": "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/data_backends.py#L80"
},
{
"name": "GitHub Issue #12625",
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/issues/12625"
},
{
"tags": [
"product"
],
"url": "https://github.com/netbox-community/netbox"
},
{
"name": "VulnCheck Advisory: NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-through-4.7.0-credential-disclosure-via-rest-and-graphql-apis"
}
],
"title": "NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-86175",
"datePublished": "2026-09-05T11:01:26.738Z",
"dateReserved": "2026-09-05T10:40:36.294Z",
"dateUpdated": "2026-09-24T14:21:15.185Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-29514 (GCVE-0-2026-29514)
Vulnerability from cvelistv5 – Published: 2026-05-04 16:05 – Updated: 2026-07-14 18:39 X_Open Source
VLAI
EPSS
VEX
Title
NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
Summary
NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox's call interception mechanism, achieving remote code execution as the NetBox service user.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-05-04 16:59 UTC
CWE
- CWE-183 - Permissive List of Allowed Inputs
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://chocapikk.com/posts/2026/netbox-export-te… | technical-descriptionexploit |
| https://github.com/netbox-community/netbox/issues/22079 | issue-tracking |
| https://github.com/netbox-community/netbox/pull/22078 | issue-tracking |
| https://github.com/netbox-community/netbox/pull/22170 | issue-tracking |
| https://github.com/netbox-community/netbox/releas… | release-notes |
| https://github.com/netbox-community/netbox/commit… | patch |
| https://www.vulncheck.com/advisories/netbox-rce-v… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| netbox-community | netbox |
Affected:
4.3.5 , ≤ 4.5.4
(semver)
cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* |
Date Public
2026-05-01 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-29514",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-04T16:59:06.882812Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-04T16:59:25.855Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "netbox",
"vendor": "netbox-community",
"versions": [
{
"lessThanOrEqual": "4.5.4",
"status": "affected",
"version": "4.3.5",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.5.4",
"versionStartIncluding": "4.3.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Valentin Lobstein (Chocapikk)"
}
],
"datePublic": "2026-05-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox\u0027s call interception mechanism, achieving remote code execution as the NetBox service user."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-183",
"description": "Permissive List of Allowed Inputs",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T18:39:54.647Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"technical-description",
"exploit"
],
"url": "https://chocapikk.com/posts/2026/netbox-export-template-rce/"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/issues/22079"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/pull/22078"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/netbox-community/netbox/pull/22170"
},
{
"tags": [
"release-notes"
],
"url": "https://github.com/netbox-community/netbox/releases/tag/v4.6.1"
},
{
"tags": [
"patch"
],
"url": "https://github.com/netbox-community/netbox/commit/d124c5fe86e12aad61285133c0caf16adcda8f2e"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/netbox-rce-via-rendertemplatemixin"
}
],
"source": {
"discovery": "EXTERNAL"
},
"tags": [
"x_open-source"
],
"title": "NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-29514",
"datePublished": "2026-05-04T16:05:33.894Z",
"dateReserved": "2026-03-04T15:39:26.872Z",
"dateUpdated": "2026-07-14T18:39:54.647Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}