{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/librenms--26.8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-86427"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LibreNMS (\u003c 26.8.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","command-injection"],"_cs_type":"advisory","_cs_vendors":["LibreNMS"],"content_html":"\u003cp\u003eLibreNMS versions prior to 26.8.0 are susceptible to an argument injection vulnerability identified as CVE-2026-86427. The vulnerability exists within the processing of the 'graph_title' parameter, where insufficient neutralization of special characters allows an authenticated attacker to break out of the intended double-quote escaping. By manipulating this parameter, an attacker can influence the execution of the 'rrdtool' utility. This allows for the injection of malicious 'DEF' and 'LINE' arguments, facilitating the unauthorized retrieval of RRD database files belonging to other monitored devices. Furthermore, the use of newline injection enables the execution of arbitrary 'rrdtool' commands, allowing attackers to bypass configured per-device authorization checks. This flaw poses a significant risk to the integrity and confidentiality of network monitoring data managed by LibreNMS.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to access sensitive network performance data from unauthorized devices or execute arbitrary commands within the context of the rrdtool process. This can lead to unauthorized information disclosure and potential escalation of control over the monitoring platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade LibreNMS instances to version 26.8.0 or later immediately to patch the argument injection vulnerability in the graph_title parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing newline characters or suspicious rrdtool flags (e.g., DEF, LINE) within the graph_title parameter string.\u003c/li\u003e\n\u003cli\u003eRestrict access to the LibreNMS monitoring interface to trusted users only to mitigate the risk from authenticated attackers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T13:36:49Z","date_published":"2026-09-07T13:36:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-librenms-argument-injection/","summary":"Authenticated attackers can exploit CVE-2026-86427 in LibreNMS before version 26.8.0 to inject arbitrary rrdtool arguments, bypassing authorization controls to read unauthorized RRD files or execute commands.","title":"Argument Injection in LibreNMS graph_title Parameter","url":"https://feed.craftedsignal.io/briefs/2026-09-librenms-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - LibreNMS (\u003c 26.8.0)","version":"https://jsonfeed.org/version/1.1"}