CVE-2026-86175CWE-522

CVE-2026-86175

Medium · published September 5, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
18.0
In the wild
Unconfirmed
What it is

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
7.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00263 · 18.0th percentile
Weakness
CWE-522 · Insufficiently Protected Credentials
Published
2026-09-05T15:16Z
References (7)
EPSS history
Timeline
  • 07 SEP 03:36Z
    EPSS moved — → 0%
    epss
  • 05 SEP 11:01Z
    NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
    cvelistv5