Reflected Cross-Site Scripting Vulnerability in LibreNMS Proxmox Application View
CVE-2026-45694

5.4MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-45694?

The LibreNMS network monitoring system contains a reflected cross-site scripting vulnerability in its Proxmox application view. In versions 26.4.0 and prior, the application fails to properly sanitize user-supplied instance and vmid GET parameters, reflecting them into the page title without sufficient encoding. The inadequate sanitization process allows an attacker to craft a malicious link. When an authenticated user clicks on this link, the injected script can execute within the user's session. This poses a significant risk as it enables the attacker to potentially steal session data and manipulate user actions. Users are advised to upgrade to version 26.5.0, where this issue has been addressed.

Affected Version(s)

librenms < 26.5.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.