CVE-2026-104073

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.6
HIGH

Description

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.

Published
October 6, 2026 7:17 PM
Last Modified
October 6, 2026 7:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-79 CWE-668

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.