CVE-2026-26987
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Description
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-79
Source
GitHub
Vendor
composer
Product
librenms/librenms
External References
- https://github.com/librenms/librenms/security/advisories/GHSA-gqx7-99jw-6fpr
- https://github.com/librenms/librenms/pull/19038
- https://github.com/librenms/librenms/commit/8e626b38ef92e240532cdac2ac7e38706a71208b
- https://github.com/librenms/librenms/releases/tag/26.2.0
- https://github.com/advisories/GHSA-gqx7-99jw-6fpr
Discussion (0)
Add Comment
No comments yet. Be the first!