LibreNMS versions prior to 26.3.0 contain an authenticated cross-site scripting (XSS) vulnerability in the showconfig page that allows attackers with administrative privileges to inject malicious scripts affecting other users with page access. The vulnerability has a CVSS score of 4.8 (Medium severity) with a network-based attack vector and low complexity, requiring high-level privileges and user interaction but capable of compromising confidentiality and integrity across multiple security domains. The vulnerability has an extremely low exploitation probability (EPSS score of 0.000040000) and is not currently listed on the Known Exploited Vulnerabilities catalog, indicating no active exploitation in the wild or public exploit availability. Given the requirement for administrative privileges and relatively low severity rating, this poses a limited risk to most LibreNMS deployments, though administrators should apply the 26.3.0 patch or later as part of routine security maintenance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 26.3.0CPE match | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | ||
< 26.3.0CPE matchmatch criteria | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.