Description
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No solution or workaround provided in the CVE record.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Netbox-community
Netbox-community netbox
Vendors & Products Netbox-community
Netbox-community netbox

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.
Title NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links
Weaknesses CWE-668
CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Netbox-community Netbox
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-07T14:11:51.535Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104073

cve-icon Vulnrichment

Updated: 2026-10-07T14:11:02.180Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:40.143

Modified: 2026-10-07T15:16:58.313

Link: CVE-2026-104073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:15:08Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')