CVE-2026-86176

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-05 11:16

Updated : 2026-09-08 20:00


NVD link : CVE-2026-86176

Mitre link : CVE-2026-86176

CVE.ORG link : CVE-2026-86176


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key