Command Injection Vulnerability in LibreNMS Network Monitoring System
CVE-2026-55182
8.6HIGH
What is CVE-2026-55182?
LibreNMS, a popular network monitoring system, has a command injection vulnerability present in versions from 21.6.0 up to 26.5.0. This flaw poses a risk as an authenticated administrator may exploit the Signal alert transport. By manipulating the Recipient field and executing crafted paths, attackers can inject malicious shell commands into the system via unsafe exec calls. Proper mitigation involves upgrading to version 26.5.0 or later, which addresses this issue comprehensively.
Affected Version(s)
librenms >= 21.6.0, < 26.5.0
