PT-2026-32330 · Librenms · Librenms

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-2728

CVSS v4.0

4.6

Medium

AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2728

Affected Products

Librenms