SB20260928430 - Multiple vulnerabilities in LibreNMS
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in an authenticated user's browser.
The vulnerability exists due to improper output encoding in the wireless sensor description display in device/wireless.inc.php when rendering sensor descriptions obtained from SNMP DisplayString values. A remote attacker can supply a crafted SNMP DisplayString through a controlled monitored device's SNMP agent to execute arbitrary JavaScript in an authenticated user's browser.
An authenticated user must visit the affected device's Wireless tab after wireless sensor discovery or polling processes the crafted value.
2) SQL injection (CVE-ID: N/A)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in includes/html/forms/notifications.inc.php when processing an array-valued notification_id parameter in a notifications read request. A remote user can submit a crafted notification_id array to perform arbitrary cross-table reads.
Read results can be persisted in notifications_attribs and retrieved through the interface.
3) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose traffic and NetFlow graph data from unauthorized devices.
The vulnerability exists due to path traversal in nfsen_channel_common.inc.php when processing the NFSen graph channel parameter. A remote user can submit a channel value containing directory traversal sequences to read RRD data for another device outside their authorized device scope.
Exploitation requires access to one NFSen-enabled device.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Tools → Oxidized node list implemented by get_oxidized_nodes_list() when rendering Oxidized API fields and SNMP sysName values. A remote privileged user can inject crafted markup into these fields to execute arbitrary script in a victim's browser.
User interaction is required to view the affected node list.
5) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to physically delete network port records.
The vulnerability exists due to missing authorization in the PortsController::purge endpoint when handling DELETE requests to /ports/purge. A remote user can send a DELETE request with a port identifier or the purge=all value to physically delete network port records.
Using purge=all deletes every previously deleted port on devices visible to the user.
Remediation
Install update from vendor's website.
References
- https://github.com/librenms/librenms/security/advisories/GHSA-ffjc-4fr5-47c6
- https://github.com/librenms/librenms/security/advisories/GHSA-2pw7-8mmj-gcw5
- https://github.com/librenms/librenms/security/advisories/GHSA-j3qf-h24w-9f42
- https://github.com/librenms/librenms/security/advisories/GHSA-cjqw-76mh-jmpv
- https://github.com/librenms/librenms/security/advisories/GHSA-9qcg-rgg9-mpjg