---
id: CVE-2026-104073
title: >-
  NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection
  vulnerability that allows a low-privileged user with the "Can add custom
  links" permission to steal session cookies and API tokens of other users by
  exposing the…
summary: >-
  NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection
  vulnerability that allows a low-privileged user with the "Can add custom
  links" permission to steal session cookies and API tokens of other users by
  exposing the…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'
cwe:
  - CWE-79
  - CWE-668
vendor: netbox-community
product: netbox
affected:
  - netbox >= 2.9.5 < 4.7.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:05:55.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104073'
references:
  - url: 'https://github.com/netbox-community/netbox/issues/22607'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/netbox-community/netbox/pull/22616'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/netbox-community/netbox/releases#release-v4.7.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netbox-session-hijacking-via-custom-links
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T19:13:33.853Z'
---

## Overview

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
