CVE-2026-27016Disclosure(librenms / librenms)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • librenms

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
librenms

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27016 Stored XSS in LibreNMS Custom OID Parameter Affecting Versions 24.10.0-26.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27016

    Post summary

    The CVE‑2026‑27016 entry describes a stored XSS vulnerability in LibreNMS’s Custom OID Parameter affecting versions 24.10.0 to 26.1.1; no proof‑of‑concept, exploit code, active exploitation, patch, or debunking claim is provided.

    0001051
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27016 LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in C… https://www.cve.org/CVERecord?id=CVE-2026-27016

    Post summary

    CVE-2026-27016 affects LibreNMS v24.10.0 through v26.1.1, introducing a stored XSS via the unit parameter; no exploit, patch, or PoC is referenced.

    0000068
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibrenmslibrenms---

Explore more