CVE-2026-84189

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 12:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-84189

Mitre link : CVE-2026-84189

CVE.ORG link : CVE-2026-84189


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')