PT-2026-32629 · Librenms · Librenms

Ömer Baran Parlak

+1

·

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-30480

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreNMS version 22.11.0-23-gd091788f2
Description A Local File Inclusion (LFI) issue exists in the NFSen module (nfsen.inc.php). This occurs due to improper restriction of the directory path name when processing the nfsen parameter. An authenticated remote attacker can use path traversal sequences to include arbitrary PHP files from the server filesystem, potentially leading to arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05375
CVE-2026-30480

Affected Products

Librenms