CVE-2026-84191: Librenms

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device can inject arbitrary JavaScript through SNMP responses that executes in the browser of any user viewing VRF-related pages.

Affected products

  • Librenms Librenms: before 26.5.0 (fixed in 26.5.0)

Published 2026-09-01. Last modified 2026-09-08.