MEDIUMVulnerability

CVE-2026-86176

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-86176
signal_observed_at
2026-09-18T21:50:21+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
published_at
2026-09-05T11:16:46.263
last_modified
2026-09-18T18:17:17.927

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86176 — Ninja Signal Threat Intelligence | Ninja Signal