CVE-2026-80214: LibreNMS Virtualisation Discovery Module RCE
Published Aug 26, 2026
·Updated
LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.
Affected Software
1 affected component
librenms librenms
Event History
Aug 26, 2026
CVE Published
via MITRE·02:11 AM
Data Sourced
via MITRE·02:11 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated as an administrative user in LibreNMS. The provided information does not indicate that lower-privileged or unauthenticated users can exploit it.
2
What is the potential impact of successful exploitation?
An authenticated administrator can inject commands through the Virtualization Discovery module and execute arbitrary code on the host server running LibreNMS.