{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/librenms-21.6.0---26.4.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LibreNMS (21.6.0 - 26.4.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LibreNMS"],"content_html":"\u003cp\u003eLibreNMS versions 21.6.0 through 26.4.x are vulnerable to a remote code execution (RCE) vulnerability (CVE-2026-55182) within the Signal Alert Transport module. The vulnerability stems from insufficient sanitization of user-provided input in the \u003ccode\u003edeliverAlert\u003c/code\u003e function located in \u003ccode\u003eLibreNMS/Alert/Transport/Signal.php\u003c/code\u003e. An authenticated administrative user can manipulate the 'Path' and 'Recipient' fields in the Alert Transport configuration to perform command injection. These inputs are passed to an unsafe \u003ccode\u003eexec\u003c/code\u003e call, which is further exacerbated by the \u003ccode\u003escripts/composer_wrapper.php\u003c/code\u003e script that accepts and executes these malicious arguments. By chaining these weaknesses, an attacker with existing administrative access can execute arbitrary commands on the underlying host server, leading to potential full system compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the LibreNMS web interface with administrative privileges.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the 'Alert Transports' configuration menu.\u003c/li\u003e\n\u003cli\u003eAttacker creates a new 'Signal' type alert transport.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the 'Path' configuration field to target \u003ccode\u003e../scripts/composer_wrapper.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker injects a command sequence starting and ending with a semicolon (\u003ccode\u003e;\u003c/code\u003e) into the 'Recipient' field.\u003c/li\u003e\n\u003cli\u003eAttacker saves the transport configuration.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the vulnerability by clicking the 'Test Transport' button associated with the malicious entry.\u003c/li\u003e\n\u003cli\u003eThe application executes the injected command via the vulnerable \u003ccode\u003eexec\u003c/code\u003e call within the backend script, resulting in RCE.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-55182 allows an authenticated attacker to achieve full remote code execution on the server hosting the LibreNMS application. This grants the attacker the ability to execute arbitrary commands with the privileges of the web service user, which can lead to data exfiltration, modification of system configurations, or lateral movement into the wider internal network. Given LibreNMS is typically deployed to monitor network infrastructure, this exposure could provide an attacker with significant visibility and control over managed network devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of LibreNMS to version 26.5.0 or later to include the vendor patch for CVE-2026-55182.\u003c/li\u003e\n\u003cli\u003eReview administrative user accounts for unauthorized activity or creation of new alert transports.\u003c/li\u003e\n\u003cli\u003eDeploy server-side auditing to monitor for unexpected child processes spawned by the web service user (e.g., \u003ccode\u003eapache\u003c/code\u003e, \u003ccode\u003ewww-data\u003c/code\u003e, \u003ccode\u003enginx\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRestrict the ability of the web service user to execute system-level binaries via sudo or system policies.\u003c/li\u003e\n\u003cli\u003eMonitor logs for the execution of \u003ccode\u003ecomposer_wrapper.php\u003c/code\u003e containing unusual characters in arguments, such as semicolons or shell operators.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T20:58:00Z","date_published":"2026-08-18T20:58:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-librenms-rce/","summary":"An authenticated administrator can execute arbitrary code on LibreNMS servers by injecting commands into the Signal Alert Transport configuration fields, triggering unsafe system exec calls.","title":"Remote Code Execution in LibreNMS Signal Alert Transport Module","url":"https://feed.craftedsignal.io/briefs/2026-08-librenms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - LibreNMS (21.6.0 - 26.4.x)","version":"https://jsonfeed.org/version/1.1"}