Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104073— NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links

Quick assessment

Affected
netbox-community netbox
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 NetBox 版本 2.9.5 到 4.7.0(不含 4.7.0)中,存在一个服务器端模板注入漏洞。该漏洞使得拥有“可添加自定义链接”权限的低权限用户,能够通过将原始的 Django HttpRequest 对象暴露给 Jinja2 模板上下文,窃取其他用户的会话 Cookie 和 API 令牌。 攻击者可以构造一个自定义链接模板,在其中嵌入 或某个用户的 API 令牌,并将其置于 img 标签的 src URL 中。这种做法会绕过 clean_html 清理器的过滤,在拥有更高权限的用户查看该对象时,自动将受

CVSS 7.6 · High EPSS 0.28% · P19

Affected Version Matrix 1

VendorProduct Version RangeStatus
netbox-community netbox 2.9.5< 4.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104073

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links
Source: CVE Program / CVE List V5
Vulnerability Description
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
将资源暴露给错误范围
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netbox-community netbox 2.9.5 ~ 4.7.0 -

II. Public POCs for CVE-2026-104073

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104073

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104073 (1)

News Coverage for CVE-2026-104073 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104073

No comments yet


Leave a comment