PT-2026-4926 · Librenms · Librenms

·

CVE-2020-36947

·

Published

2026-01-27

·

Updated

2026-02-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreNMS version 1.46
Description LibreNMS version 1.46 contains an authenticated SQL injection issue in the MAC accounting graph endpoint. This allows remote attackers to extract database information by manipulating the sort parameter with crafted SQL injection techniques, enabling time-based blind SQL injection. The affected API endpoint is the MAC accounting graph endpoint.
Recommendations Apply a fix or patch for LibreNMS version 1.46 to address the SQL injection issue in the MAC accounting graph endpoint. As a temporary workaround, restrict access to the MAC accounting graph endpoint or sanitize the sort parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36947
GHSA-QP2J-V5JG-HG68

Affected Products

Librenms