CVE-2026-26988

CRITICAL LAB

LibreNMS <=25.12.0 - SQL Injection

Title source: llm

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the address parameter is split into an address and a prefix, and the prefix portion is directly concatenated into the SQL query string without validation. This allows an attacker to inject arbitrary SQL commands, potentially leading to unauthorized data access or database manipulation. This issue has been fixed in version 26.2.0.

Exploits (3)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-26988
github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2026-26988
nomisec WORKING POC
by mbanyamer · poc
https://github.com/mbanyamer/CVE-2026-26988-LibreNMS-SQLi

Scores

CVSS v3 9.1
EPSS 0.0000
EPSS Percentile 0.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Lab Environment

Lab screenshot
patched
docker pull ghcr.io/exploitintel/cve-2026-26988-patched:latest
All Labs GitHub

Classification

CWE
CWE-89
Status published

Affected Products (1)

librenms/librenms < 26.2.0

Timeline

Published Feb 20, 2026
Tracked Since Feb 20, 2026