MEDIUM 5.3 NVD

CVE-2026-86176

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticat

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.

References

Published: 2026-09-05 · Source: NVD · Feed updated: 2026-09-05
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-05 via NVD.
vulnfeed aggregates 10223 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.