Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108715
CVE-2026-108715
Description
LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in includes/html/graphs/smokeping/auth.inc.php that checks the src probe device instead of the rendered target device. Restricted users permitted on a probe device can request smokeping_in or smokeping_out graphs with arbitrary device ids to view latency data and enumerate device names.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/librenms/librenms/blob/26.9.1.1/LibreNMS/Util/Graph.phpnvd
- github.com/librenms/librenms/blob/26.9.1.1/includes/html/graphs/smokeping/auth.inc.phpnvd
- hackmd.io/@haind/librenms-smokeping-graph-src-device-auth-confusionnvd
- www.vulncheck.com/advisories/librenms-through-26.9.1.1-authorization-bypass-via-smokeping-graph-auth-inc-phpnvd
News mentions
0No linked articles in our index yet.