Executive brief
NetBox is a network infrastructure management platform used by organizations to track and automate network resources. An ORM injection vulnerability allows authenticated users, including those with read-only API access, to extract sensitive data from the database and bypass security permissions across all modules. An attacker could exfiltrate confidential network configuration details or gain unauthorized access to restricted information.
Technical details
The vulnerability is an ORM (Object-Relational Mapping) injection flaw in the WritableNestedSerializer component of NetBox's REST API. Attackers can inject arbitrary Django ORM lookup expressions by crafting malicious JSON dictionary keys in POST, PUT, or PATCH requests to any REST API endpoint. No special privileges are required—attackers with read-only API tokens can exploit this. The flaw enables boolean-based blind data extraction from sensitive fields and allows circumventing object-level permission checks across dcim, ipam, tenancy, virtualization, circuits, and extras modules. A patch was released in commit b3489cd to enforce object permissions for nested related objects.
Affected products
- NetBox NetBox 4.5.8
Timeline
- 2026-08-11: disclosed
- 2026-06-22: patched: Fix applied in commit b3489cd before disclosure