Skip to content
Threat Feed

Vendor

LibreNMS

6 briefs RSS
high advisory

Argument Injection in LibreNMS graph_title Parameter

Authenticated attackers can exploit CVE-2026-86427 in LibreNMS before version 26.8.0 to inject arbitrary rrdtool arguments, bypassing authorization controls to read unauthorized RRD files or execute commands.

LibreNMS vulnerability web-application command-injection
1r 1t 1c
high advisory

Stored XSS via SNMP and Syslog in LibreNMS

LibreNMS is vulnerable to stored cross-site scripting (XSS) due to improper output encoding of SNMP-polled data and syslog messages in legacy PHP templates, allowing attackers to execute arbitrary JavaScript in the browsers of authenticated users.

LibreNMS
1r 1t 1c updated
high advisory

Remote Code Execution in LibreNMS Signal Alert Transport Module

An authenticated administrator can execute arbitrary code on LibreNMS servers by injecting commands into the Signal Alert Transport configuration fields, triggering unsafe system exec calls.

LibreNMS +1 xss web-vulnerability
3t
high advisory

Multiple Vulnerabilities in LibreNMS

LibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.

LibreNMS web-application vulnerability rce ssrf xss
1t
medium threat

LibreNMS Multiple XSS Vulnerabilities

Multiple reflected cross-site scripting (XSS) vulnerabilities exist in LibreNMS versions 25.12.0 to before 26.3.0, allowing an attacker to inject malicious code into a user's browser session.

LibreNMS xss reflected-xss
2r 1t
high advisory

LibreNMS Remote Code Execution via Arbitrary File Write

An authenticated administrator can achieve remote code execution on LibreNMS by modifying the binary path settings for built-in network tools and bypassing an input filter to execute arbitrary commands.

LibreNMS rce web-application
2r 1t 1i