top of page
perceptive_background_267k.jpg

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without esc…

Published:

1 september 2026 om 00:00:00

Alert date:

1 september 2026 om 15:04:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies, Security Tools

LibreNMS versions prior to 26.3.1 are affected by a stored cross-site scripting (XSS) vulnerability in legacy PHP templates. The vulnerability arises because SNMP-sourced and syslog-sourced data are output without proper escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript payloads through SNMP interface descriptions or syslog program fields. These payloads execute in the browser context of authenticated users who view the affected pages. The attack vector requires the attacker to control a device being monitored by the LibreNMS instance. Exploitation could lead to session hijacking, credential theft, or further lateral movement within the network management environment. Users are strongly advised to upgrade to LibreNMS 26.3.1 or later to remediate the vulnerability. The issue has been disclosed via GitHub Security Advisories and tracked by VulnCheck.

Technical details

Mitigation steps:

Affected products:

LibreNMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page