Reflected XSS Vulnerability in LibreNMS Network Monitoring Tool
CVE-2026-26987
5.3MEDIUM
What is CVE-2026-26987?
LibreNMS, an auto-discovering network monitoring tool based on PHP/MySQL/SNMP, is exposed to reflected cross-site scripting (XSS) attacks due to improper handling of input in the email field. This vulnerability affects versions 25.12.0 and earlier, allowing attackers to inject malicious scripts that could be executed in the context of users accessing the application. Upgrading to version 26.2.0 mitigates this issue.
Affected Version(s)
librenms < 26.2.0
