LibreNMS versions prior to 26.3.0 contain an authenticated remote code execution vulnerability that can be exploited by abusing the Binary Locations configuration option and the Netcommand feature. Successful exploitation requires administrative privileges and could lead to complete compromise of the underlying web server, including confidentiality, integrity, and availability impacts. The vulnerability has a CVSS score of 7.2 (HIGH) with a network-based attack vector and low attack complexity. The network-accessible nature of LibreNMS and the absence of user interaction requirements mean that an authenticated administrator could execute arbitrary code with minimal friction once access is obtained. There is currently no evidence of active exploitation in the wild, as indicated by the lack of KEV (Known Exploited Vulnerability) designation and its inactive status on security hotlists. The EPSS score of 0.00005 suggests minimal real-world exploitation probability relative to other CVEs, though organizations running vulnerable versions should prioritize patching to version 26.3.0 or later given the severity of potential impacts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 26.3.0CPE match | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | ||
< 26.3.0CPE matchmatch criteria | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.