OS Command Injection in LibreNMS - #VU140844

 

OS Command Injection in LibreNMS - #VU140844

Published: August 4, 2026


Vulnerability identifier: #VU140844
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary OS commands.

The vulnerability exists due to command injection in VminfoLibvirt.php when processing a device hostname during libvirt discovery. A remote privileged user can supply a crafted hostname and trigger discovery to execute arbitrary OS commands.

Only instances with libvirt support enabled are vulnerable, and code execution occurs in the discovery worker context as the librenms user.


Affected software

LibreNMS

Remediation

Install security update from vendor's website.

LibreNMS - update to 26.4.0

External References

Related Security Bulletins