SB2026080414 - OS Command Injection in LibreNMS



SB2026080414 - OS Command Injection in LibreNMS

Published: August 4, 2026

Security Bulletin ID SB2026080414
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) OS Command Injection (CVE-ID: N/A)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary OS commands.

The vulnerability exists due to command injection in VminfoLibvirt.php when processing a device hostname during libvirt discovery. A remote privileged user can supply a crafted hostname and trigger discovery to execute arbitrary OS commands.

Only instances with libvirt support enabled are vulnerable, and code execution occurs in the discovery worker context as the librenms user.


Remediation

Install update from vendor's website.