CVE-2026-84191: LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields

Published Sep 1, 2026
·
Updated

LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrfname, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device can inject arbitrary JavaScript through SNMP responses that executes in the browser of any user viewing VRF-related pages.

Affected Software

1 affected component
librenms librenms<26.5.0

Event History

Sep 1, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

LibreNMS installations before 26.5.0 are exposed when they poll monitored devices that provide attacker-controlled values in VRF-related SNMP fields. Any user who views the affected VRF display pages may have injected JavaScript execute in their browser.

2

What does an attacker need to exploit it?

An attacker needs control of a monitored network device, or otherwise needs to control its SNMP responses. Exploitation also requires a user to visit a VRF-related page that renders the stored values.

3

Which SNMP data fields should be investigated?

Review VRF-related SNMP data for unexpected or untrusted content in mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher. These are the fields identified as being rendered without sanitization.

4

How can exposure be reduced if an upgrade is not immediately possible?

Limit monitoring to trusted devices and prevent untrusted parties from controlling monitored-device SNMP responses. Restrict access to VRF-related LibreNMS pages to reduce the chance that users render malicious stored values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203