SQL injection in LibreNMS - #VU152691
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in includes/html/forms/notifications.inc.php when processing an array-valued notification_id parameter in a notifications read request. A remote user can submit a crafted notification_id array to perform arbitrary cross-table reads.
Read results can be persisted in notifications_attribs and retrieved through the interface.