Reflected Cross-Site Scripting Vulnerability in LibreNMS Proxmox Application View
CVE-2026-45694
5.4MEDIUM
What is CVE-2026-45694?
The LibreNMS network monitoring system contains a reflected cross-site scripting vulnerability in its Proxmox application view. In versions 26.4.0 and prior, the application fails to properly sanitize user-supplied instance and vmid GET parameters, reflecting them into the page title without sufficient encoding. The inadequate sanitization process allows an attacker to craft a malicious link. When an authenticated user clicks on this link, the injected script can execute within the user's session. This poses a significant risk as it enables the attacker to potentially steal session data and manipulate user actions. Users are advised to upgrade to version 26.5.0, where this issue has been addressed.
Affected Version(s)
librenms < 26.5.0
