


Perceptive Security
SOC/SIEM Consultancy

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without esc…
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 15:04:21
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies, Security Tools
LibreNMS versions prior to 26.3.1 are affected by a stored cross-site scripting (XSS) vulnerability in legacy PHP templates. The vulnerability arises because SNMP-sourced and syslog-sourced data are output without proper escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript payloads through SNMP interface descriptions or syslog program fields. These payloads execute in the browser context of authenticated users who view the affected pages. The attack vector requires the attacker to control a device being monitored by the LibreNMS instance. Exploitation could lead to session hijacking, credential theft, or further lateral movement within the network management environment. Users are strongly advised to upgrade to LibreNMS 26.3.1 or later to remediate the vulnerability. The issue has been disclosed via GitHub Security Advisories and tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
LibreNMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84192
https://github.com/librenms/librenms/security/advisories/GHSA-7w8c-qgxg-m7jx
https://www.vulncheck.com/advisories/librenms-before-26.3.1-stored-xss-via-snmp-syslog-data
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
