Stored Cross-Site Scripting in LibreNMS Affected by Unescaped SNMP and Syslog Data
CVE-2026-84192

7.1HIGH

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84192?

LibreNMS versions earlier than 26.3.1 are susceptible to a stored cross-site scripting vulnerability found within legacy PHP templates. The flaw arises from the improper handling of data sourced from SNMP interfaces and syslog program fields, which are presented to users without necessary escaping. This allows an attacker controlling a network device to inject harmful JavaScript, which can be executed when authenticated users access affected web pages. It's crucial for users of LibreNMS to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

librenms 0 < 26.3.1

librenms 26.3.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TristanInSec
.