CVE-2020-15874: Command Injection
Published Aug 26, 2026
·Updated
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
Affected Software
1 affected component
librenms librenms=1.65
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be remote, authenticated, and have normal LibreNMS privileges. No administrative privileges are stated as necessary.
2
Which interface is involved in exploitation?
The command injection is in the /graph.php API endpoint. Systems where authenticated normal users can access this endpoint are relevant to triage.
3
What version should be used to remediate the issue?
The provided references include a comparison from LibreNMS 1.65 to 1.65.1 and the 1.65.1 release. Updating from 1.65 to 1.65.1 addresses the referenced issue.