CVE-2026-84193: LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP

Published Sep 1, 2026
·
Updated

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.

Affected Software

1 affected component
LibreNMS<=26.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LibreNMS to a version that resolves this vulnerability.

    Fixed in 26.2.0
  2. Compensating control

    If you have enrollable SNMP discovery/device management, restrict/enforce access so attackers cannot enroll a rogue SNMP device (limit SNMP enrollment/discovery and management access to trusted networks/admins only).

Event History

Sep 1, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can inject the malicious data?

An attacker needs device management access, or network access sufficient to enroll a rogue SNMP device. The injected values can include BGP peer descriptions, VRF names, process information, and SLA tags.

2

Which users are at risk when the payload is triggered?

Administrators who view affected routing or device pages can trigger the stored JavaScript. Successful execution can enable theft of credentials and exfiltration of CSRF tokens.

3

How can I determine whether an instance may be affected?

Instances running LibreNMS through 26.2.0 may be affected if they use the legacy PHP template pages that render SNMP-sourced fields. Review SNMP-discovered values, especially BGP peer descriptions, VRF names, process information, and SLA tags, for unexpected script-like content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203