Librenms · Librenms · CVE-2026-84193
**Name of the Vulnerable Software and Affected Versions**
LibreNMS versions prior to 26.2.1
**Description**
Stored cross-site scripting occurs in legacy PHP template pages that render unescaped data fields sourced from SNMP, such as BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or the ability to enroll a rogue SNMP device can inject malicious JavaScript. This script executes when administrators view affected routing and device pages, potentially leading to credential theft and CSRF (Cross-Site Request Forgery) token exfiltration.
**Recommendations**
Update LibreNMS to version 26.2.1 or later.