Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0. | |
| Title | LibreNMS before 26.7.0 Stored XSS via Oxidized API | |
| First Time appeared |
Librenms
Librenms librenms |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Librenms
Librenms librenms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T11:33:54.590Z
Reserved: 2026-09-01T10:51:59.728Z
Link: CVE-2026-84189
No data.
Status : Received
Published: 2026-09-01T12:17:48.287
Modified: 2026-09-01T12:17:48.287
Link: CVE-2026-84189
No data.
OpenCVE Enrichment
Updated: 2026-09-01T12:30:04Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')