Default Credentials Vulnerability in NetBox Docker by NetBox Community
CVE-2023-27573

9CRITICAL

Key Information:

Vendor
CVE Published:
11 March 2026

What is CVE-2023-27573?

NetBox Docker prior to version 2.5.0 contains a vulnerability where the superuser account is configured with default credentials, including a common password for the admin account and a pre-set API token. While many users altered the default admin password, approximately 10% neglected to change the SUPERUSER_API_TOKEN, leaving their systems vulnerable. Although the use of default values was intended for isolated environments, some users attempted to deploy it in production without altering these settings. The installation process does not enforce the requirement to change the defaults, increasing the risk of unauthorized access.

Affected Version(s)

netbox-docker 0 < 2.5.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.