CVE-2026-86175
moderatePlaintext Credential Exposure in NetBox REST/GraphQL Data Source API
NetBox through 4.7.0 fails to redact sensitive credentials for Git and Amazon S3 data source backends in REST and GraphQL API responses (CWE-522, Insufficiently Protected Credentials). An attacker needs only a valid low-privilege account with view permission; querying the affected API endpoints over the network returns backend passwords and secret keys in plaintext. With those credentials, an attacker gains unauthorized access to the external Git repositories and S3 buckets that the NetBox instance integrates with, extending the impact beyond the NetBox instance itself. Any deployment running version 4.7.0 or earlier where untrusted or minimally privileged users hold view access and data source backends are configured is affected. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Upgrade NetBox to the first release published after 4.7.0 that restores credential redaction for data source backends, as no fixed version is specified in the available data. Until then, limit view permissions on data source objects to trusted staff, audit API tokens held by low-privilege users, and check API access logs for data source queries by non-administrative accounts. If untrusted users had view access to instances with Git or S3 backends, rotate those backend credentials and review repository and bucket access logs for signs of unauthorized use.
| NetBox (open-source project) NetBox | all versions through and including 4.7.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.