Input validation error in LibreNMS - #VU140840
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to write arbitrary files and execute arbitrary code.
The vulnerability exists due to improper input validation in LibreNMS/OS/Traits/VminfoLibvirt.php when using an administrator-controlled virsh binary path during discovery jobs. A remote user can set the virsh path to another executable and supply crafted configuration values to write arbitrary files and execute arbitrary code.
Exploitation requires administrative access to change binary location settings, and code execution may depend on hosting a malicious device or otherwise making a payload reachable to the server.