PT-2026-84152 · Librenms · Librenms

·

CVE-2026-84189

·

Published

2026-08-04

·

Updated

2026-09-01

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 26.7.0
Description The software fails to apply htmlspecialchars() when rendering JSON fields returned by the admin-configurable Oxidized integration URL (oxidized.url) on the device showconfig page. If an administrator points this URL to an attacker-controlled server, it can lead to Server-Side Request Forgery (SSRF) and the return of malicious JSON. This results in stored cross-site scripting (XSS), which affects all users who view the showconfig tab of any device.
Recommendations Update to version 26.7.0 or later.

Exploit

Fix

SSRF

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13728
CVE-2026-84189
GHSA-7GWW-X7FH-JF9J

Affected Products

Librenms