← Back to overview

LibreNMS versions through 26.4.0 are vulnerable to stored/persistent cross-site scripting (XSS) due to improper output encoding of JSON fields returned by the admin-configurable Oxidized integration URL. Specifically, fields such as name, ip, model, author, and commit message are rendered into the device showconfig page without applying htmlspecialchars(). An administrator who configures the Oxidized URL to point at an attacker-controlled server (leveraging SSRF) can cause malicious JSON to be returned and stored, affecting all users who view any device's showconfig tab. The vulnerability requires administrator-level access to configure the malicious URL, but its impact extends to all users of the platform. The issue has been patched in LibreNMS version 26.7.0. References are available via the NVD, GitHub Security Advisory, and VulnCheck advisory pages.

Affected products

  • LibreNMS

Related CVE's

  • CVE-2026-84189

Categories

  • Network Infrastructure
  • Security Tools
  • Web Technologies