PT-2026-86400 · Netbox · Netbox
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetBox versions prior to 4.7.1
Description
Authenticated users with view permissions can access private records of all users due to improper scoping of querysets. This issue affects the REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks, disclosing which users watch or bookmark specific objects.
Recommendations
Update NetBox to version 4.7.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netbox