NetBox Cross-Site Scripting Vulnerability Advisory
Summary
CERT-Bund has issued a security advisory for NetBox, detailing a vulnerability that allows for Cross-Site Scripting attacks. The advisory affects NetBox version 4.3.5 and provides information on mitigation strategies.
What changed
CERT-Bund has released security advisory WID-SEC-2026-0736 concerning a critical vulnerability in NetBox, specifically affecting version 4.3.5. The vulnerability, rated with a CVSS Base Score of 6.1, allows remote, anonymous attackers to perform Cross-Site Scripting (XSS) attacks. The advisory applies to NetBox installations running on Linux and UNIX operating systems.
Organizations using NetBox version 4.3.5 should immediately review their systems for potential compromise and apply available security patches or mitigations as recommended by the vendor. While the advisory does not specify a compliance deadline, prompt action is advised to prevent exploitation and maintain the security of network documentation and management infrastructure. Failure to address this vulnerability could lead to unauthorized access or data manipulation.
What to do next
- Review NetBox installations for version 4.3.5.
- Apply vendor-provided security patches or mitigations for the XSS vulnerability.
- Monitor for further updates from CERT-Bund or NetBox regarding this vulnerability.
Source document (simplified)
[WID-SEC-2026-0736] NetBox: Schwachstelle ermöglicht Cross-Site Scripting CVSS Base Score 6.1 (mittel) CVSS Temporal Score 5.6 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation nein
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
Produktbeschreibung
NetBox ist eine Lösung zur Modellierung und Dokumentation moderner Netzwerke.
Produkte
16.03.2026
- Open Source NetBox 4.3.5
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NetBox ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.