PT-2026-84153 · Librenms · Librenms

·

CVE-2026-84190

·

Published

2026-08-18

·

Updated

2026-09-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 26.5.0
Description An authenticated administrator can achieve remote code execution via the AboutController. The issue occurs because the snmpget configuration parameter is passed to the shell exec() function without proper validation. An attacker can modify the snmpget configuration to point to a malicious executable and trigger its execution by accessing the '/about' endpoint.
Recommendations Update to version 26.5.0 or later. Restrict access to the '/about' endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84190
GHSA-JF24-8G2H-2WG7

Affected Products

Librenms