Vulnerability Description
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.
Related Weaknesses (CWE)
References
- https://github.com/librenms/librenms/security/advisories/GHSA-v5jp-f342-234h
- https://www.vulncheck.com/advisories/librenms-through-26.2.0-stored-cross-site-s
- https://github.com/librenms/librenms/security/advisories/GHSA-v5jp-f342-234h
FAQ
What is CVE-2026-84193?
CVE-2026-84193 is a documented vulnerability. LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, pro...
How severe is CVE-2026-84193?
CVSS scoring is not yet available for CVE-2026-84193. Check NVD for updates.
Is there a patch for CVE-2026-84193?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.