CVE-2026-84192: Librenms

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.

Affected products

  • Librenms Librenms: before 26.3.1 (fixed in 26.3.1)

Published 2026-09-01. Last modified 2026-10-08.