SB2026080414 - OS Command Injection in LibreNMS
Published: August 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) OS Command Injection (CVE-ID: N/A)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary OS commands.
The vulnerability exists due to command injection in VminfoLibvirt.php when processing a device hostname during libvirt discovery. A remote privileged user can supply a crafted hostname and trigger discovery to execute arbitrary OS commands.
Only instances with libvirt support enabled are vulnerable, and code execution occurs in the discovery worker context as the librenms user.
Remediation
Install update from vendor's website.