CVE Explorer
CVE-2026-26991
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an HTTP POST request is sent to the Request-URI "/device-groups". The name of the newly created device group is stored in the value of the name parameter. After the device group is created, the entry is displayed along with
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"librenms","vendor":"librenms","versions":[{"status":"affected","version":"< 26.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/librenms/librenms/commit/64b31da444369213eb4559ec1c304ebfaa0ba12c","tags":["x_refsource_MISC"],"url":"https://github.com/librenms/librenms/commit/64b31da444369213eb4559ec1c304ebfaa0ba12c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/references/2
{"name":"https://github.com/librenms/librenms/pull/19041","tags":["x_refsource_MISC"],"url":"https://github.com/librenms/librenms/pull/19041"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/references/1
{"name":"https://github.com/librenms/librenms/releases/tag/26.2.0","tags":["x_refsource_MISC"],"url":"https://github.com/librenms/librenms/releases/tag/26.2.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/references/3
{"name":"https://github.com/librenms/librenms/security/advisories/GHSA-5pqf-54qp-32wx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/librenms/librenms/security/advisories/GHSA-5pqf-54qp-32wx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b905d5dcf7a90db90e23920553470e9ef16bcbe3ec7fe4a40d84635e81b0263e · sha256:692f0bd44ef4c0fc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.