SB2026061542 - Multiple vulnerabilities in LibreNMS
Published: June 15, 2026 Updated: August 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Command injection (CVE-ID: N/A)
CWE-ID: CWE-77 - Command injection
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in the Signal alert transport module and scripts/composer_wrapper.php when adding and testing an alert transport entry with crafted Path and Recipient values. A remote user can supply specially crafted transport settings to execute arbitrary code.
Exploitation requires administrative access to create and test an alert transport entry.
2) Cross-site scripting (CVE-ID: CVE-2026-45694)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in LegacyController.php document.title JavaScript assignment when handling crafted Proxmox instance and vmid GET parameters. A remote user can send a specially crafted link to execute arbitrary script in the victim's browser.
User interaction is required, and the victim must follow a crafted link. An authenticated session is required.
3) OS Command Injection (CVE-ID: N/A)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in an os command in the AboutController /about endpoint when executing the configured snmpget binary path via shell_exec(). A remote privileged user can modify the snmpget configuration to point to a malicious executable and access the /about endpoint to execute arbitrary code.
Exploitation requires administrator access to the web interface and the ability to place an executable file on the target system.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the VRF display pages when rendering SNMP-sourced VRF fields in HTML and JavaScript contexts. A remote attacker can supply specially crafted SNMP field values to execute arbitrary script in a victim's browser.
User interaction is required to view VRF-related pages.
5) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the VLAN name display page when rendering SNMP-sourced VLAN names in HTML. A remote attacker can supply a specially crafted VLAN name to execute arbitrary script in a victim's browser.
The advisory identifies this as an additional vulnerable entry point following the same SNMP-sourced data flow pattern.
Remediation
Install update from vendor's website.
References
- https://github.com/librenms/librenms/security/advisories/GHSA-c9fv-cgmm-2wg7
- https://github.com/librenms/librenms/security/advisories/GHSA-jmqm-f8q4-v7wx
- https://github.com/librenms/librenms/security/advisories/GHSA-jf24-8g2h-2wg7
- https://github.com/librenms/librenms/security/advisories/GHSA-g993-wffj-m3gv