Medium severity5.4NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026
CVE-2026-27016
CVE-2026-27016
Description
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
librenms/librenmsPackagist | >= 24.10.0, < 26.2.0 | 26.2.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335nvdPatchWEB
- github.com/advisories/GHSA-fqx6-693c-f55gghsaADVISORY
- github.com/librenms/librenms/security/advisories/GHSA-fqx6-693c-f55gnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-27016ghsaADVISORY
- github.com/librenms/librenms/pull/19040nvdIssue TrackingWEB
- github.com/librenms/librenms/releases/tag/26.2.0nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.