Argument Injection Vulnerability in LibreNMS by LibreNMS
CVE-2026-86427

8.7HIGH

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86427?

LibreNMS versions prior to 26.8.0 are susceptible to an argument injection flaw arising from improper handling of the graph_title parameter. This vulnerability permits authenticated attackers to break out of double-quote escaping, enabling them to inject arbitrary rrdtool arguments. By exploiting this weakness, attackers can read RRD files from devices they should not have access to, or execute arbitrary rrdtool commands, effectively bypassing authorization controls that are meant to enforce per-device permissions.

Affected Version(s)

librenms 0 < 26.8.0

librenms 26.8.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.