Path traversal in LibreNMS - #VU152692
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose traffic and NetFlow graph data from unauthorized devices.
The vulnerability exists due to path traversal in nfsen_channel_common.inc.php when processing the NFSen graph channel parameter. A remote user can submit a channel value containing directory traversal sequences to read RRD data for another device outside their authorized device scope.
Exploitation requires access to one NFSen-enabled device.