PT-2026-84156 · Librenms · Librenms

·

CVE-2026-84193

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

5.8

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 26.2.1
Description Stored cross-site scripting occurs in legacy PHP template pages that render unescaped data fields sourced from SNMP, such as BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or the ability to enroll a rogue SNMP device can inject malicious JavaScript. This script executes when administrators view affected routing and device pages, potentially leading to credential theft and CSRF (Cross-Site Request Forgery) token exfiltration.
Recommendations Update LibreNMS to version 26.2.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84193
GHSA-V5JP-F342-234H

Affected Products

Librenms