CVE-2026-86176
Received Received - Intake

NetBox API Private Record Exposure via Unscoped Querysets

Vulnerability report for CVE-2026-86176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: VulnCheck

Description

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
netbox netbox to 4.7.0 (inc)
netbox netbox 4.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NetBox through version 4.7.0 has an information disclosure vulnerability in its REST and GraphQL APIs. Authenticated users with view permissions can access private records of other users through unscoped querysets. This affects Notifications, Subscriptions, and Bookmarks endpoints, revealing which users monitor or bookmark specific objects.

Detection Guidance

To detect this vulnerability, check NetBox API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access private records via unscoped queries. Review API logs for unusual queries targeting these endpoints. No specific commands are provided in the context.

Impact Analysis

This vulnerability allows attackers with valid credentials to view sensitive information about other users' activities. They can see which objects other users are watching or bookmarking, potentially exposing private data or user behavior patterns. This could lead to privacy breaches or targeted attacks against specific users.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for data protection and access controls. It enables unauthorized access to user data, which could result in non-compliance with privacy regulations. Organizations using affected NetBox versions may face legal and regulatory penalties for failing to protect sensitive user information.

Mitigation Strategies

Upgrade NetBox to a version beyond 4.7.0 to address the improper scoping issue. Ensure strict permission checks are enforced for API endpoints. Review and restrict access to Notifications, Subscriptions, and Bookmarks endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart