PT-2026-80762 · Librenms · Librenms
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreNMS versions 21.6.0 through 26.4.0
Description
An authenticated administrator can execute arbitrary operating-system commands on the host server. The issue occurs because the
deliverAlert function in LibreNMS/Alert/Transport/Signal.php insufficiently escapes the signal-cli path and the Recipient field before passing them to an exec call. By pointing the path to the composer wrapper.php script, which also contains unsafe exec calls, an attacker can chain these calls to achieve remote code execution.Recommendations
Update to version 26.5.0.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librenms