{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alibrenmslibrenms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-84189"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LibreNMS (\u003c 26.5.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LibreNMS"],"content_html":"\u003cp\u003eLibreNMS versions prior to 26.5.0 contain multiple stored cross-site scripting (XSS) vulnerabilities within legacy PHP templates located in the \u003ccode\u003eincludes/html/\u003c/code\u003e directory. The vulnerability stems from the direct echoing of data retrieved from SNMP-monitored network devices and incoming syslog messages without appropriate output encoding or escaping.\u003c/p\u003e\n\u003cp\u003eSpecific components impacted include the syslog viewer, alert details page, and device health monitoring dashboards (mempool, storage, and sensors). An attacker with the ability to modify SNMP interface descriptions (ifAlias) or send arbitrary syslog traffic to the LibreNMS server can inject malicious JavaScript. When an authenticated LibreNMS administrator or user views these dashboards, the payload executes within their browser context. This allows attackers to perform actions on behalf of the user, potentially including credential theft or unauthorized configuration changes within the monitoring platform. The issue is exacerbated by the platform's reliance on legacy PHP templates that bypass the auto-escaping features present in newer Blade-based templates.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes control over a network device or syslog-capable host monitored by the target LibreNMS instance.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the SNMP \u003ccode\u003eifAlias\u003c/code\u003e (interface description) or sends a crafted syslog \u003ccode\u003eprogram\u003c/code\u003e string containing a JavaScript payload (e.g., \u003ccode\u003e\u0026lt;img src=x onerror=\u0026quot;fetch('...')\u0026quot;\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eLibreNMS performs its scheduled SNMP discovery/polling cycle or receives the syslog packet.\u003c/li\u003e\n\u003cli\u003eThe unescaped, malicious string is stored directly into the LibreNMS SQL database (e.g., the \u003ccode\u003eports\u003c/code\u003e table or \u003ccode\u003esyslog\u003c/code\u003e table).\u003c/li\u003e\n\u003cli\u003eAn authenticated LibreNMS user navigates to the affected web interface (e.g., Alerts page, Health dashboard, or Syslog view).\u003c/li\u003e\n\u003cli\u003eThe legacy PHP template fetches the malicious string from the database and echoes it raw into the HTML response.\u003c/li\u003e\n\u003cli\u003eThe victim's web browser renders the HTML and executes the attacker's JavaScript payload within the context of the user session.\u003c/li\u003e\n\u003cli\u003eAttacker achieves unauthorized execution, such as data exfiltration or session manipulation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an attacker to compromise the sessions of authenticated users, which can lead to unauthorized access to the network monitoring platform. Given that LibreNMS often holds high-privileged credentials and visibility into sensitive infrastructure, successful exploitation could facilitate lateral movement, information gathering, or operational disruption. The impact is significant for organizations using LibreNMS as a central visibility tool for core network components.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all LibreNMS installations to version 26.5.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected characters or script tags in SNMP interface descriptions or syslog program fields.\u003c/li\u003e\n\u003cli\u003eRestrict access to SNMP configuration and syslog submission channels to trusted IP ranges to prevent unauthorized data injection.\u003c/li\u003e\n\u003cli\u003eUse the webserver log source to monitor for unusual POST/GET patterns directed at health, alert, and syslog endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T13:06:17Z","date_published":"2026-08-26T20:20:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-librenms-xss/","summary":"LibreNMS is vulnerable to stored cross-site scripting (XSS) due to improper output encoding of SNMP-polled data and syslog messages in legacy PHP templates, allowing attackers to execute arbitrary JavaScript in the browsers of authenticated users.","title":"Stored XSS via SNMP and Syslog in LibreNMS","url":"https://feed.craftedsignal.io/briefs/2026-08-librenms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}