CVE 5.3 MEDIUM

LibreNMS affected by reflected XSS via email field_CVE-2026-26987

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.

Basic Information

ID CVE-2026-26987
Source GitHub_M
Published Feb 20, 2026 at 01:11

Affected Product

Vendor librenms
Product librenms
Version < 26.2.0
Affected Versions librenms librenms < 26.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.