Command injection in LibreNMS - #VU140839
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in LibreNMS/OS/Traits/VminfoLibvirt.php when processing administrator-controlled libvirt username or protocol settings during discovery jobs. A remote user can inject shell commands through the virtualization module configuration to execute arbitrary code.
Exploitation requires administrative access to modify the relevant settings, and the injected commands are triggered when a poller starts a discovery job.