Authorization Bypass in LibreNMS Affects Smokeping Graphs
CVE-2026-108715
5.3MEDIUM
What is CVE-2026-108715?
LibreNMS versions up to 26.9.1.1 are impacted by an authorization bypass vulnerability that occurs due to improper checks in the Smokeping graph functionality. The system incorrectly verifies the source probe device instead of the intended target device, allowing restricted users to access smokeping_in and smokeping_out graphs. This flaw enables unauthorized users to request graphs using arbitrary device IDs, granting them the ability to view sensitive latency data and enumerate device names, thereby posing significant risks to network security and data privacy.
Affected Version(s)
librenms 0 <= 26.9.1.1
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
