PT-2026-32331 · Librenms · Librenms

Yurinek0

·

Published

2026-03-26

·

Updated

2026-04-13

·

CVE-2026-6204

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreNMS versions prior to 26.3.0
Description An authenticated administrator can execute arbitrary code on the host server by abusing the Binary Locations configuration and the Netcommand feature. The application allows administrative users to configure absolute binary paths for network diagnostic tools at the '/settings/external/binaries' endpoint, but it does not sufficiently validate that these paths remain restricted to safe executables. These tools are invoked via the 'GET /ajax/netcmd' endpoint. Although an input filter exists to restrict arguments to valid IP addresses or hostnames, this filter can be bypassed, allowing an attacker to download and execute malicious payloads, potentially leading to a complete compromise of the underlying web server.
Recommendations Update to version 26.3.0 or later. As a temporary workaround, restrict access to the '/settings/external/binaries' configuration to minimize the risk of unauthorized binary path modification.

Exploit

Fix

RCE

OS Command Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6204
GHSA-7549-GGPQ-22W8
GHSA-PR3G-PHHR-H8FH

Affected Products

Librenms