CVE-2026-84192

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 12:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-84192

Mitre link : CVE-2026-84192

CVE.ORG link : CVE-2026-84192


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')