Command injection in LibreNMS - #VU140839

 

Command injection in LibreNMS - #VU140839

Published: August 4, 2026


Vulnerability identifier: #VU140839
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in LibreNMS/OS/Traits/VminfoLibvirt.php when processing administrator-controlled libvirt username or protocol settings during discovery jobs. A remote user can inject shell commands through the virtualization module configuration to execute arbitrary code.

Exploitation requires administrative access to modify the relevant settings, and the injected commands are triggered when a poller starts a discovery job.


Affected software

LibreNMS

Remediation

Install security update from vendor's website.

LibreNMS - update to 26.4.1

External References

Related Security Bulletins