CVE-2026-26990: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-26990 is a time-based blind SQL injection vulnerability in LibreNMS affecting the address-search.inc.php file via the address parameter. It was disclosed on February 17, 2026, and affects all LibreNMS versions prior to 26.2.0 (specifically <= 25.12.0 per the security advisory). The vulnerability was reported by researcher quirmz and published to the GitHub Advisory Database on February 18, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, LibreNMS Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In includes/html/table/address-search.inc.php, the user-controlled $prefix variable — extracted from the address POST parameter by splitting on / — is concatenated directly into SQL queries on lines 34 and 52 without sanitization or parameterized binding: $sql .= " AND ipv4_prefixlen='$prefix'" and $sql .= " AND ipv6_prefixlen = '$prefix'". An attacker sends a crafted POST request to /ajax_table.php with a malicious address value such as 127.0.0.1/aa<payload>, injecting time-based MySQL payloads (e.g., using IF(..., SLEEP(n), 0)) to infer database contents character by character. Authentication is required, but any valid user account — regardless of privilege level — can exploit this endpoint (LibreNMS Advisory, GitHub Advisory).

Impact

Successful exploitation allows any authenticated user to extract the full contents of the LibreNMS back-end database through time-based inference, including schema information, application data, and sensitive user records. Most critically, an attacker can retrieve administrative usernames and their associated password hashes, which — if cracked — yield plaintext admin credentials and enable full privilege escalation within LibreNMS. The CVSS score reflects high impact across confidentiality, integrity, and availability (LibreNMS Advisory, GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) Python script is included in the official security advisory, demonstrating automated time-based blind SQL injection using binary search to extract arbitrary database values character by character. As of the advisory publication date, there is no evidence of active in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.003% (0th percentile), indicating a currently low probability of exploitation in the next 30 days (LibreNMS Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain valid credentials: Acquire any authenticated LibreNMS account (even a low-privilege "tester" role is sufficient).
  2. Authenticate to LibreNMS: Send a GET request to /login to retrieve the CSRF _token, then POST credentials to /login to establish an authenticated session cookie (laravel_session).
  3. Identify the vulnerable endpoint: Target POST /ajax_table.php with parameters id=address-search, search_type=ipv4, and a crafted address value.
  4. Inject time-based payload: Supply an address value of the form 127.0.0.1/aa' AND (SELECT 1 FROM (SELECT IF(LENGTH((SELECT CURRENT_USER()))=<n>,SLEEP(3),0))x) AND '1'='1 to determine the length of the target value via response timing.
  5. Extract data character by character: Use a binary search algorithm with payloads like ' AND (SELECT 1 FROM (SELECT IF(ASCII(SUBSTRING((<query>),<pos>,1))=<char>,SLEEP(3),0))x) AND '1'='1 to retrieve each character of the target database value.
  6. Retrieve admin credentials: Query the users table to extract administrative usernames and password hashes (e.g., SELECT password FROM users WHERE username='admin').
  7. Crack password hashes: Use offline tools (e.g., Hashcat, John the Ripper) to crack retrieved hashes and obtain plaintext admin credentials for full privilege escalation (LibreNMS Advisory).

Indicators of compromise

  • Network: Repeated POST requests to /ajax_table.php with id=address-search and address parameter values containing SQL metacharacters (single quotes, AND, SELECT, SLEEP, IF, ASCII, SUBSTRING).
  • Network: Unusually slow HTTP responses (e.g., 3–6 seconds) to /ajax_table.php from the same source IP, consistent with time-delay injection probing.
  • Logs: Web server access logs showing high-frequency POST requests to /ajax_table.php from a single authenticated session, with address field values containing /aa followed by encoded SQL syntax.
  • Logs: Application or database slow-query logs recording repeated SLEEP() function calls or conditional time-delay queries against ipv4_addresses or ipv6_addresses tables.
  • Logs: Authentication logs showing a low-privilege account logging in followed immediately by a burst of requests to the address search endpoint.

Mitigation and workarounds

LibreNMS has released version 26.2.0 (patched versions also referenced as 26.1 in the security advisory) which rewrites the address search backend using a modern controller-based architecture with proper parameterized queries, eliminating the unsafe string concatenation (LibreNMS Advisory, Fix Commit). All users running versions <= 25.12.0 should upgrade immediately. As interim mitigations, administrators should implement WAF rules to detect and block SQL injection patterns in POST parameters, restrict network access to the LibreNMS web interface to trusted users only, and audit all user accounts to remove unnecessary access.

Community reactions

The vulnerability was covered by The Hacker Wire, which published a dedicated article on the LibreNMS time-based blind SQL injection (The Hacker Wire). A Bluesky post from The Hacker Wire's account also highlighted the disclosure. Check Point published a defense advisory (CPAI-2026-1322) referencing the vulnerability. Community reaction has been limited given the low EPSS score and absence of in-the-wild exploitation evidence.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management