CVE-2020-15874

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.

Published 2026-08-26. Last modified 2026-09-03.