Command Injection Vulnerability in LibreNMS Network Monitoring System
CVE-2026-55182

8.6HIGH

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-55182?

LibreNMS, a popular network monitoring system, has a command injection vulnerability present in versions from 21.6.0 up to 26.5.0. This flaw poses a risk as an authenticated administrator may exploit the Signal alert transport. By manipulating the Recipient field and executing crafted paths, attackers can inject malicious shell commands into the system via unsafe exec calls. Proper mitigation involves upgrading to version 26.5.0 or later, which addresses this issue comprehensively.

Affected Version(s)

librenms >= 21.6.0, < 26.5.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.