SB2026082537 - Multiple vulnerabilities in LibreNMS
Published: August 25, 2026 Updated: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Validation of Specified Type of Input (CVE-ID: CVE-2026-86426)
CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and access the REST API with the privileges of a matched token owner.
The vulnerability exists due to improper validation of specified type of input in the API token authentication check when processing JSON-supplied api_token values. A remote attacker can send a specially crafted API request with a numeric or array-typed token value to bypass authentication and access the REST API with the privileges of a matched token owner.
Exploitation requires that at least one enabled API token already exists on the target system.
CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information and tamper with monitoring data.
The vulnerability exists due to improper neutralization of special elements in the graph_title parameter in Rrd::graph() command construction when handling crafted graph requests. A remote user can inject double quotes or newline characters into the graph_title query parameter to disclose sensitive information and tamper with monitoring data.
If unauthenticated graph access is enabled, authentication is not required. Newline injection can cause additional rrdtool commands to be processed in stdin mode.
Remediation
Install update from vendor's website.