Vulnerabilities
CVE-2026-26992 - LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name
CVE ID : CVE-2026-26992 Published : Feb. 20, 2026, 3:16 a.m. | 1 hour, 29 minutes ago Description : LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP POST request is sent to the Request-URI
CVE Details
CVE ID
Published
Feb. 20, 2026
Affected Product:
PHP
Attack Vector:
network
Impact:
XSS