Authentication Bypass in LibreNMS REST API by Numeric Type Confusion
CVE-2026-86426
9.2CRITICAL
What is CVE-2026-86426?
LibreNMS versions prior to 26.8.0 are susceptible to an authentication bypass vulnerability in the REST API. This issue arises when attackers exploit MySQL type coercion by submitting small integer values (0 through 9) instead of string tokens. By leveraging this weakness, unauthorized individuals can access restricted API endpoints, thereby gaining unauthorized access to critical functionalities such as device credentials and administrative features. This exposure can ultimately lead to remote code execution via manipulated alert templates.
Affected Version(s)
librenms 0 < 26.8.0
librenms 26.8.0
