CVE-2023-33796: Netbox
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.
Affected products
- Netbox Netbox: version 3.5.1 only
Published 2023-05-24. Last modified 2026-06-17.