github.com
https://github.com/librenms/librenms CVE-2026-6204
HIGH
LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write
Record summary
CVE-2026-6204 has a selected CVSS score of 8.5 (high).
Description
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 13, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
librenmsBrowse librenms / librenmsDefault status: unaffected | CVE List | Before 26.3.0 | affected |
librenms/librenmsBrowse Packagist / librenms/librenms | GitHub Advisory | 1.48 to < 26.3.0 · Fixed in 26.3.0 | affected |
References
5github.com
https://github.com/librenms/librenms/blob/master/app/Providers/AppServiceProvider.php github.comVendor advisory
https://github.com/librenms/librenms/security/advisories/GHSA-pr3g-phhr-h8fh nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6204 projectblack.ioexploit
https://projectblack.io/blog/librenms-authenticated-rce-and-xss