← Back to overview

LibreNMS versions before 26.8.0 are affected by an argument injection vulnerability in the graph_title parameter. Authenticated attackers can break out of double-quote escaping to inject arbitrary rrdtool arguments. By injecting DEF and LINE arguments, attackers can read RRD files from devices they are not authorized to access. Additionally, newline injection can be used to execute arbitrary rrdtool commands, effectively bypassing per-device authorization checks. The vulnerability requires authentication but can lead to unauthorized data access and command execution within the rrdtool context. A fix is available in LibreNMS version 26.8.0 and later. Security advisories have been published on GitHub and VulnCheck detailing the issue and remediation steps.

Affected products

  • LibreNMS

Related CVE's

  • CVE-2026-86427

Categories

  • Network Infrastructure
  • Security Tools
  • Web Technologies