CVE-2026-84188

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 12:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-84188

Mitre link : CVE-2026-84188

CVE.ORG link : CVE-2026-84188


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')