Stored Cross-Site Scripting Vulnerability in LibreNMS by LibreNMS
CVE-2026-84189

9.2CRITICAL

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84189?

LibreNMS versions prior to 26.7.0 are susceptible to a stored cross-site scripting vulnerability. This issue arises when JSON fields such as name, IP, model, author, and commit message are rendered on the device showconfig page without proper HTML entity escaping (htmlspecialchars()). If an administrator configures the Oxidized integration URL to point to a malicious server, an attacker can exploit this weakness to inject harmful scripts. As a result, any user viewing the affected device's showconfig tab is at risk of having their session compromised or sensitive information stolen. The vulnerability has been addressed in version 26.7.0.

Affected Version(s)

librenms 0 < 26.7.0

librenms 26.7.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

k1bana
.