Reflected XSS Vulnerability in LibreNMS Network Monitoring Tool
CVE-2026-26987

5.3MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
20 February 2026

What is CVE-2026-26987?

LibreNMS, an auto-discovering network monitoring tool based on PHP/MySQL/SNMP, is exposed to reflected cross-site scripting (XSS) attacks due to improper handling of input in the email field. This vulnerability affects versions 25.12.0 and earlier, allowing attackers to inject malicious scripts that could be executed in the context of users accessing the application. Upgrading to version 26.2.0 mitigates this issue.

Affected Version(s)

librenms < 26.2.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.