What is CVE-2026-69117?
NetBox 4.5.8 contains an ORM injection vulnerability allowing authenticated users, including those with read-only API tokens, to inject Django ORM lookup expressions via crafted JSON dictionary keys in REST API requests. This may lead to unauthorized data access. Upgrading to the latest version is recommended.
Azərbaycanca: NetBox 4.5.8-də autentifikasiya olunmuş istifadəçilərə (yalnız oxuma API tokenləri daxil) xüsusi JSON açar adları vasitəsilə Django ORM lookup injection etməyə imkan verən boşluq aşkarlanıb. Bu, REST API sorğuları ilə icazəsiz məlumat əldə etməyə səbəb ola bilər. NetBox-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Is authentication required to exploit CVE-2026-69117?
Yes, this vulnerability can only be exploited by authenticated users, including those with read-only API tokens.
Which version of NetBox is affected by CVE-2026-69117?
This vulnerability has been identified in NetBox version 4.5.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.