Changeflow GovPing Data Privacy & Cybersecurity NetBox Cross-Site Scripting Vulnerability Advisory
Priority review Notice Added Final

NetBox Cross-Site Scripting Vulnerability Advisory

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 16th, 2026
Detected March 17th, 2026
Email

Summary

CERT-Bund has issued a security advisory for NetBox, detailing a vulnerability that allows for Cross-Site Scripting attacks. The advisory affects NetBox version 4.3.5 and provides information on mitigation strategies.

What changed

CERT-Bund has released security advisory WID-SEC-2026-0736 concerning a critical vulnerability in NetBox, specifically affecting version 4.3.5. The vulnerability, rated with a CVSS Base Score of 6.1, allows remote, anonymous attackers to perform Cross-Site Scripting (XSS) attacks. The advisory applies to NetBox installations running on Linux and UNIX operating systems.

Organizations using NetBox version 4.3.5 should immediately review their systems for potential compromise and apply available security patches or mitigations as recommended by the vendor. While the advisory does not specify a compliance deadline, prompt action is advised to prevent exploitation and maintain the security of network documentation and management infrastructure. Failure to address this vulnerability could lead to unauthorized access or data manipulation.

What to do next

  1. Review NetBox installations for version 4.3.5.
  2. Apply vendor-provided security patches or mitigations for the XSS vulnerability.
  3. Monitor for further updates from CERT-Bund or NetBox regarding this vulnerability.

Source document (simplified)

[WID-SEC-2026-0736] NetBox: Schwachstelle ermöglicht Cross-Site Scripting CVSS Base Score 6.1 (mittel) CVSS Temporal Score 5.6 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation nein

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX

Produktbeschreibung

NetBox ist eine Lösung zur Modellierung und Dokumentation moderner Netzwerke.

Produkte

16.03.2026
- Open Source NetBox 4.3.5

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NetBox ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 16th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
de

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Network Management

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.