Stored Cross-Site Scripting Vulnerability in LibreNMS by LibreNMS
CVE-2026-84189
9.2CRITICAL
What is CVE-2026-84189?
LibreNMS versions prior to 26.7.0 are susceptible to a stored cross-site scripting vulnerability. This issue arises when JSON fields such as name, IP, model, author, and commit message are rendered on the device showconfig page without proper HTML entity escaping (htmlspecialchars()). If an administrator configures the Oxidized integration URL to point to a malicious server, an attacker can exploit this weakness to inject harmful scripts. As a result, any user viewing the affected device's showconfig tab is at risk of having their session compromised or sensitive information stolen. The vulnerability has been addressed in version 26.7.0.
Affected Version(s)
librenms 0 < 26.7.0
librenms 26.7.0
