Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-4068

37
FAUCET Score

CVE-2022-4068 affects LibreNMS, allowing a low-privileged user to re-enable their own account if an administrator disabled it, provided they maintain a valid session. More critically, the vulnerability includes a stored Cross-Site Scripting (XSS) flaw (CWE-79) in the admin user overview due to improper username sanitization. This XSS allows an attacker to execute arbitrary JavaScript in an administrator's browser, potentially leading to unauthorized actions. Rated Medium severity with a CVSS score of 5.4, the attack requires low privileges and user interaction (UI:R), but its impact is limited to partial confidentiality and integrity (C:L/I:L). The EPSS score of 0.54367 indicates a higher-than-average probability of exploitation compared to most CVEs. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received no community discussion or media coverage, suggesting a low level of public awareness or attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 22.10.0CPE matchmatch criteria
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.6HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.1
Impact Score
5.5
CvssVersion
3.0

Exploit Intelligence

EPSS Score
33.97%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.3397 is in the 99th percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: librenms/librenmsFixed in: 22.10.0
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-f3hw-3h74-wr98high

Cross-site Scripting in librenms/librenms

Nov 20, 2022

References

github.com / librenms/librenms/commit/09a2977adb8bc4b1db116c725d661160c930d3a1
PatchThird Party Advisory
huntr.dev / bounties/becfecc4-22a6-4f94-bf83-d6030b625fdc
ExploitPatchThird Party Advisory