Argument Injection Vulnerability in LibreNMS by LibreNMS
CVE-2026-86427
8.7HIGH
What is CVE-2026-86427?
LibreNMS versions prior to 26.8.0 are susceptible to an argument injection flaw arising from improper handling of the graph_title parameter. This vulnerability permits authenticated attackers to break out of double-quote escaping, enabling them to inject arbitrary rrdtool arguments. By exploiting this weakness, attackers can read RRD files from devices they should not have access to, or execute arbitrary rrdtool commands, effectively bypassing authorization controls that are meant to enforce per-device permissions.
Affected Version(s)
librenms 0 < 26.8.0
librenms 26.8.0
