CVE-2026-29514PoC

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize parameter to any importable Python callable such as subprocess.getoutput, which is invoked on every rendered expression outside the sandbox's call interception mechanism, achieving remote code execution as the NetBox service user.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-183

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-19: 1Mentions · 2026-06-03: 1Mentions · 2026-06-13: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-06-13: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-13: 105-1906-0306-13
Signal classification2 categories
PoC
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-191
PoC1
2026-06-031
Disclosure1
2026-06-131
PoC1
Full discourse3 posts
  • Densel@luckyhacker43
    PoC

    CVE-2026-29514: NetBox Jinja2 Sandbox Bypass to RCE via RenderTemplateMixin environment_params 👾💥 👨‍💻 Valentin Lobstein (ʞʞıdɐɔoɥƆ) 🔗 https://chocapikk.com/posts/2026/netbox-export-template-rce/ Join team 👉https://t.me/luckyhacker43 https://t.co/eYHW3tRFrZ

    Post summary

    This post announces CVE-2026-29514, a NetBox Jinja2 sandbox bypass that enables remote code execution, and links to a proof‑of‑concept demonstrating the vulnerability.

    020219786
    2.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. The Sandbox That Never Was: CVE-2026-29514 Turns NetBox Template Engine Into Code Execution

    Post summary

    The tweet announces CVE-2026-29514, highlighting it enables code execution via the NetBox template engine, but offers no PoC, exploit code, or patch details.

    1000034
    239 followersView on X
  • N45HT@N45HTOfficial
    PoC

    CVE-2026-29514: NetBox Jinja2 Sandbox Bypass to RCE via RenderTemplateMixin environment_params 👾💥 👨‍💻 Valentin Lobstein (ʞʞıdɐɔoɥƆ) 🔗 https://chocapikk.com/posts/2026/netbox-export-template-rce/ https://t.co/r06iIIm6hV

    Post summary

    CVE‑2026‑29514 is a NetBox Jinja2 sandbox bypass that results in remote code execution; a proof of concept is provided via the linked blog post, with no mention of patches or active exploitation.

    0000074
    92 followersView on X

Explore more