Input validation error in LibreNMS - #VU140840

 

Input validation error in LibreNMS - #VU140840

Published: August 4, 2026


Vulnerability identifier: #VU140840
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to write arbitrary files and execute arbitrary code.

The vulnerability exists due to improper input validation in LibreNMS/OS/Traits/VminfoLibvirt.php when using an administrator-controlled virsh binary path during discovery jobs. A remote user can set the virsh path to another executable and supply crafted configuration values to write arbitrary files and execute arbitrary code.

Exploitation requires administrative access to change binary location settings, and code execution may depend on hosting a malicious device or otherwise making a payload reachable to the server.


Affected software

LibreNMS

Remediation

Install security update from vendor's website.

LibreNMS - update to 26.4.1

External References

Related Security Bulletins