CVE-2026-26990Disclosure(librenms / librenms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch librenms librenms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in address-search.inc.php via the address parameter. When a crafted subnet prefix is supplied, the prefix value is concatenated directly into an SQL query without proper parameter binding, allowing an attacker to manipulate query logic and infer database information through time-based conditional responses. This vulnerability requires authentication and is exploitable by any authenticated user. This issue has been fixedd in version 26.2.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • librenms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-20); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
librenms

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-20: 4Mentions · 2026-02-25: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 4Technical Details · 2026-02-25: 102-2002-25
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-204
Disclosure3Patch1
2026-02-251
Disclosure1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26990 Time-Based Blind SQL Injection in LibreNMS Address Search Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26990

    Post summary

    This brief notice announces a new CVE, CVE-2026-26990, describing a time-based blind SQL injection flaw in LibreNMS's address search module, but provides no PoC, exploit code, or mitigation details.

    0001042
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26990 (CVSS:8.8, HIGH) is Analyzed. LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Bas..https://nvd.nist.gov/vuln/detail/CVE-2026-26990 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post reports on CVE-2026-26990, noting its high severity (CVSS 8.8) and affected LibreNMS versions, but provides no PoC, exploit, or patch details.

    0000035
    172 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26990: HIGH] LibreNMS network monitoring tool had Time-Based Blind SQL Injection vulnerability in versions 25.12.0 and below, fixed in version 26.2.0. Ensure prompt updates for cyber security.#cve,CVE-2026-26990,#cybersecurity https://cvefind.com/CVE-2026-26990

    Post summary

    The text announces a Time‑Based Blind SQL Injection flaw (CVE‑2026‑26990) in LibreNMS that has been fixed in v26.2.0 and recommends users to update promptly.

    0000042
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26990 LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in addres… https://www.cve.org/CVERecord?id=CVE-2026-26990

    Post summary

    CVE‑2026‑26990 exposes a Time‑Based Blind SQL Injection in LibreNMS versions 25.12.0 and earlier; the vulnerability is described but not linked to PoC, exploit code, or active attacks.

    0000083
    56.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26990 - High LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulnerability in http://address-search.inc.php via the ... https://www.thehackerwire.com/vulnerability/CVE-2026-26990/ https://t.co/SdXJx2ExMT

    Post summary

    The post discloses a time‑based blind SQL injection flaw in LibreNMS 25.12.0 and earlier, specifically through address-search.inc.php, but does not provide PoC code, exploit details, patch information, or evidence of active exploitation.

    0000062
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibrenmslibrenms---

Explore more