Vendor
Argument Injection in LibreNMS graph_title Parameter
1 rule 1 TTP 1 CVEAuthenticated attackers can exploit CVE-2026-86427 in LibreNMS before version 26.8.0 to inject arbitrary rrdtool arguments, bypassing authorization controls to read unauthorized RRD files or execute commands.
Stored XSS via SNMP and Syslog in LibreNMS
1 rule 1 TTP 1 CVELibreNMS is vulnerable to stored cross-site scripting (XSS) due to improper output encoding of SNMP-polled data and syslog messages in legacy PHP templates, allowing attackers to execute arbitrary JavaScript in the browsers of authenticated users.
Remote Code Execution in LibreNMS Signal Alert Transport Module
3 TTPsAn authenticated administrator can execute arbitrary code on LibreNMS servers by injecting commands into the Signal Alert Transport configuration fields, triggering unsafe system exec calls.
Multiple Vulnerabilities in LibreNMS
1 TTPLibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.
LibreNMS Multiple XSS Vulnerabilities
2 rules 1 TTPMultiple reflected cross-site scripting (XSS) vulnerabilities exist in LibreNMS versions 25.12.0 to before 26.3.0, allowing an attacker to inject malicious code into a user's browser session.
LibreNMS Remote Code Execution via Arbitrary File Write
2 rules 1 TTP 1 IOCAn authenticated administrator can achieve remote code execution on LibreNMS by modifying the binary path settings for built-in network tools and bypassing an input filter to execute arbitrary commands.