๐Ÿ” CVE Alert

CVE-2026-104073

HIGH 7.6

NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.

CWE CWE-668 CWE-79
Vendor netbox-community
Product netbox
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for netbox-community netbox

Be the first to know when new high vulnerabilities affecting netbox-community netbox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

netbox-community / netbox
2.9.5 < 4.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netbox-community/netbox/releases#release-v4.7.0 github.com: https://github.com/netbox-community/netbox/issues/22607 github.com: https://github.com/netbox-community/netbox/pull/22616 vulncheck.com: https://www.vulncheck.com/advisories/netbox-session-hijacking-via-custom-links

Credits

Nguyen Hoang VulnCheck