Vulnerability Description
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface descriptions or syslog program fields that executes when authenticated users view affected pages.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/librenms/librenms/security/advisories/GHSA-7w8c-qgxg-m7jx
- https://www.vulncheck.com/advisories/librenms-before-26.3.1-stored-xss-via-snmp-
- https://github.com/librenms/librenms/security/advisories/GHSA-7w8c-qgxg-m7jx
FAQ
What is CVE-2026-84192?
CVE-2026-84192 is a vulnerability with a CVSS score of 7.1 (HIGH). LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monito...
How severe is CVE-2026-84192?
CVE-2026-84192 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84192?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.