Vulnerability Description
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632
- https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-graph
- https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632
FAQ
What is CVE-2026-84188?
CVE-2026-84188 is a vulnerability with a CVSS score of 4.8 (MEDIUM). LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/...
How severe is CVE-2026-84188?
CVE-2026-84188 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84188?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.