CVE-2026-26987

MEDIUM

LibreNMS <25.12.0 - XSS

Title source: llm
STIX 2.1

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version 26.2.0.

Scores

CVSS v3 6.1
EPSS 0.0000
EPSS Percentile 0.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
librenms/librenms < 26.2.0
librenms/librenms 0 - 26.2.0Packagist
Published Feb 20, 2026
Tracked Since Feb 20, 2026