CVE-2026-84189: LibreNMS before 26.7.0 Stored XSS via Oxidized API

Published Sep 1, 2026
·
Updated

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0.

Affected Software

1 affected component
librenms librenms<26.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LibreNMS to a version that resolves this vulnerability.

    Fixed in 26.7.0
  2. Configuration

    Ensure JSON fields returned by the Oxidized integration URL (oxidized.url) are rendered on the device showconfig tab with htmlspecialchars() to prevent stored/persistent XSS (fields include name, ip, model, author, commit message) as the fix for versions before 26.7.0.

    LibreNMS Oxidized integration (oxidized.url) htmlspecialchars() = applied

Event History

Sep 1, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

LibreNMS instances through 26.4.0 are exposed when the administrator-configurable oxidized.url integration endpoint is set to an attacker-controlled server. The resulting persistent XSS affects users who view any device's showconfig tab.

2

What does an attacker need to exploit it?

An administrator must first configure the Oxidized integration URL to point to an attacker-controlled server. That server can then return malicious JSON values in fields such as name, ip, model, author, or commit message, which LibreNMS renders without HTML escaping.

3

Is the default configuration affected?

The available information identifies exploitation through the admin-configurable oxidized.url integration URL. It does not state that a default Oxidized configuration points to an attacker-controlled endpoint.

4

What can be done if upgrading is not immediately possible?

Do not configure oxidized.url to an attacker-controlled or otherwise untrusted server. Restrict that integration endpoint to trusted Oxidized services and prevent it from being redirected to attacker-controlled infrastructure.

5

How can I determine whether the issue may already have been triggered?

Review the configured oxidized.url value and determine whether it has pointed to an attacker-controlled or untrusted server. Also inspect device showconfig pages for unexpected content originating from Oxidized JSON fields, including name, ip, model, author, and commit message.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203