PT-2026-32331 · Librenms · Librenms

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2026-6204

CVSS v4.0

8.5

High

AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6204

Affected Products

Librenms