Junglewise Threat Intelligence

CVE-2026-2728: LibreNMS authenticated XSS in showconfig page

CVE-2026-2728 · Severity: medium · CVSS 4.8 · Published 2026-04-13

Technologies: Librenms, librenms/librenms (Packagist). Vendors: Librenms, Packagist.

Executive brief

LibreNMS is an open-source network monitoring system used to manage and track the health of IT infrastructure. A security vulnerability in its configuration interface allows an administrator to inject malicious scripts into the system's settings. In environments with multiple administrators, a compromised or malicious staff member could use this to hijack the sessions of other IT managers or steal sensitive operational data when they view device configuration pages.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS within the ShowConfig page for devices utilizing RANCID integration. The root cause is a failure to sanitize the 'rancid_repo_url' configuration value before rendering it within an HTML anchor tag in 'includes/html/pages/device/showconfig.inc.php'. An authenticated attacker with permissions to modify external settings can inject a payload into the 'rancid_repo_url' field. When another user navigates to the affected device's configuration page, the unsanitized input is executed as JavaScript in their browser context. This is classified as an Admin-to-Admin XSS. The issue is fixed in version 26.3.0.

Affected products

  • LibreNMS LibreNMS >= 25.12.0, < 26.3.0

Timeline

  • 2026-05-12: patched: Version 26.3.0 released
  • 2026-05-18: advisory: GitHub Advisory published

References

Related threats