← Terug naar overzicht

LibreNMS versions prior to 26.5.0 contain a remote code execution vulnerability in the AboutController component. The snmpget configuration parameter is passed directly to shell_exec() without proper sanitization or validation. An authenticated administrator can exploit this by modifying the snmpget configuration to reference a malicious executable. Code execution is then triggered by simply accessing the /about endpoint. The vulnerability requires administrator-level authentication, limiting the attack surface but not eliminating the risk. Fixes are available in LibreNMS version 26.5.0 and later. The issue is documented across NVD, GitHub Security Advisories, and VulnCheck.

Affected products

  • LibreNMS

Related CVE's

  • CVE-2026-84190

Categories

  • Network Infrastructure
  • Security Tools
  • Web Technologies