Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netbox-community
Netbox-community netbox |
|
| Vendors & Products |
Netbox-community
Netbox-community netbox |
Sat, 05 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets. | |
| Title | NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs | |
| First Time appeared |
Netbox
Netbox netbox |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:netbox:netbox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netbox
Netbox netbox |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T13:13:33.718Z
Reserved: 2026-09-05T10:40:36.294Z
Link: CVE-2026-86175
Updated: 2026-09-08T13:13:15.865Z
Status : Awaiting Analysis
Published: 2026-09-05T11:16:46.123
Modified: 2026-09-08T20:00:18.870
Link: CVE-2026-86175
No data.
OpenCVE Enrichment
Updated: 2026-09-07T08:25:12Z