CVE intelligence
CVE-2026-86176
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bo
Published 2026-09-05 · CVSS CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
medium
NIST record