CVE-2026-26991 - LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-g...

CVE-2026-26991 - LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-g...

CVE ID : CVE-2026-26991 Published : Feb. 20, 2026, 3:15 a.m. | 1 hour, 29 minutes ago Description : LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an HTTP POST request is sent to the Request-URI

CVE Details

Published
Feb. 20, 2026
Affected Product: PHP
Attack Vector: network
Impact: XSS