LibreNMS 在 26.5.0 之前的版本中存在一个远程代码执行(RCE)漏洞,位于 AboutController 中。该漏洞是由于 配置参数在未经过充分验证的情况下被直接传递给 函数所致。已认证的管理员可以将 配置修改为指向一个恶意的可执行文件,并通过访问 端点来触发代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84194 | 8.6 HIGH | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname |
| CVE-2026-84189 | 8.1 HIGH | LibreNMS before 26.7.0 Stored XSS via Oxidized API |
| CVE-2026-84192 | 7.1 HIGH | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data |
| CVE-2026-84191 | 6.1 MEDIUM | LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields |
| CVE-2026-84193 | 5.8 MEDIUM | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP |
| CVE-2026-84188 | 4.8 MEDIUM | librenms before 26.7.0 Stored XSS via graph_descr settings |
No comments yet