LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-01 12:17
Updated : 2026-09-08 20:18
NVD link : CVE-2026-84192
Mitre link : CVE-2026-84192
CVE.ORG link : CVE-2026-84192
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
