Missing Authorization in LibreNMS - #VU152694
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to physically delete network port records.
The vulnerability exists due to missing authorization in the PortsController::purge endpoint when handling DELETE requests to /ports/purge. A remote user can send a DELETE request with a port identifier or the purge=all value to physically delete network port records.
Using purge=all deletes every previously deleted port on devices visible to the user.