PT-2026-20904 · Librenms · Librenms

Quirmz

·

Published

2026-02-18

·

Updated

2026-02-20

·

CVE-2026-26989

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions 25.12.0 and below
Description LibreNMS, an auto-discovering PHP/MySQL/SNMP based network monitoring tool, contains a Stored Cross-Site Scripting (XSS) issue in the Alert Rules workflow. An attacker with administrative privileges can inject malicious scripts that execute in the browser context of any user who accesses the Alert Rules page. This allows for the execution of arbitrary code within a user's browser session.
Recommendations Update to version 26.2.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-26989
GHSA-6XMX-XR9P-58P7

Affected Products

Librenms