Deserialization Vulnerability in NetBox Device Type Library
CVE-2026-54752

9.6CRITICAL

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54752?

The NetBox Device Type Library allows unauthenticated contributors to exploit a deserialization vulnerability through manipulated pickle files. This flaw can lead to arbitrary code execution during pytest runs, potentially compromising the confidentiality, integrity, and availability of valuable resources. The vulnerability arises from an oversight in the validation mechanisms within the read_pickle_data function. It is crucial for users to update and secure their systems against this risk to prevent unauthorized access and safeguard sensitive data.

Affected Version(s)

devicetype-library < 1c6f7e2b93589b965318c6e67ac3504831f0e71e

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.