5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.
Basic Information
ID
CVE-2026-26987
Source
GitHub_M
Published
Feb 20, 2026 at 01:11
Affected Product
Vendor
librenms
Product
librenms
Version
< 26.2.0
Affected Versions
librenms librenms < 26.2.0