CVE-2026-84190: Librenms

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget configuration to point to a malicious executable file and trigger code execution by accessing the /about endpoint.

Affected products

  • Librenms Librenms: before 26.5.0 (fixed in 26.5.0)

Published 2026-09-01. Last modified 2026-10-08.