


Perceptive Security
SOC/SIEM Consultancy

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 …
Published:
10 maart 2026 om 23:00:00
Alert date:
11 maart 2026 om 14:02:13
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access, Enterprise Applications
CVE-2023-27573 affects netbox-docker versions before 2.5.0, which contains a superuser account with default credentials including an admin password and a hardcoded SUPERUSER_API_TOKEN. While nearly all users changed the default password, only about 90% changed the API token when deploying to production environments. The vulnerability was intentional for development use but became a security risk when users repurposed the product for production without changing defaults. The issue was resolved in version 2.5.0.
Technical details
Mitigation steps:
Affected products:
netbox-docker
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2023-27573
https://github.com/netbox-community/netbox-docker/issues/953
https://github.com/netbox-community/netbox-docker/pull/959
https://github.com/netbox-community/netbox-docker/releases/tag/2.5.0
Related CVE's:
Related threat actors:
IOC's:
0123456789abcdef0123456789abcdef01234567
This article was created with the assistance of AI technology by Perceptive.
