Cross-site scripting in LibreNMS - CVE-2026-2728
Published: May 18, 2026
LibreNMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the ShowConfig page when rendering the rancid_repo_url configuration value in an HTML anchor tag. A remote privileged user can inject a crafted configuration value to execute arbitrary script code in a victim's browser.
User interaction is required when a user visits the affected device configuration page.