← Back

CVE-2026-27016

nvd nist
Published: Feb 20, 2026Modified: Feb 20, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: security-advisories@github.com (Secondary)

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.

Affected (1)

Products: Librenms: Librenms
1 product
Librenms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 24.10.0 to 26.2.0

References (4)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
Third Party Advisory

Timeline

No history available yet.