NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets. | |
| Title | NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs | |
| First Time appeared |
Netbox
Netbox netbox |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netbox
Netbox netbox |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T11:01:26.738Z
Reserved: 2026-09-05T10:40:36.294Z
Link: CVE-2026-86175
No data.
Status : Received
Published: 2026-09-05T11:16:46.123
Modified: 2026-09-05T11:16:46.123
Link: CVE-2026-86175
No data.
OpenCVE Enrichment
Updated: 2026-09-05T12:30:04Z
Weaknesses