CVE-2026-86175 PUBLISHED

NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 05.09.2026 Updated: 05.09.2026

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor netbox-community
Product netbox
Versions Default: unaffected
  • affected from 0 to 4.7.0 (incl.)

Credits

  • George Chen reporter

References

Problem Types

  • Insufficiently Protected Credentials CWE