- EPSS 0.28%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This af...
CVE-2026-86427
- EPSS 0.32%
- Veröffentlicht 07.09.2026 12:53:48
- Zuletzt bearbeitet 18.09.2026 18:33:07
LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arg...
CVE-2026-86426
- EPSS 0.56%
- Veröffentlicht 07.09.2026 12:53:47
- Zuletzt bearbeitet 18.09.2026 18:37:30
LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion b...
CVE-2026-84193
- EPSS 0.27%
- Veröffentlicht 01.09.2026 11:33:57
- Zuletzt bearbeitet 08.09.2026 20:18:59
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with dev...
CVE-2026-84194
- EPSS 1.39%
- Veröffentlicht 01.09.2026 11:33:57
- Zuletzt bearbeitet 08.09.2026 20:18:59
LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this->getDevice()->hostname) is...
CVE-2026-84192
- EPSS 0.24%
- Veröffentlicht 01.09.2026 11:33:56
- Zuletzt bearbeitet 08.10.2026 16:17:54
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript...
CVE-2026-84190
- EPSS 0.6%
- Veröffentlicht 01.09.2026 11:33:55
- Zuletzt bearbeitet 08.10.2026 16:17:54
LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget ...
CVE-2026-84191
- EPSS 0.19%
- Veröffentlicht 01.09.2026 11:33:55
- Zuletzt bearbeitet 08.09.2026 20:18:59
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling...
CVE-2026-84189
- EPSS 0.27%
- Veröffentlicht 01.09.2026 11:33:54
- Zuletzt bearbeitet 08.10.2026 16:17:54
LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who...
CVE-2026-84188
- EPSS 0.18%
- Veröffentlicht 01.09.2026 11:33:53
- Zuletzt bearbeitet 08.10.2026 16:17:54
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a...