VYPR
Medium severity5.4NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026

CVE-2026-27016

CVE-2026-27016

Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping. This issue is fixed in version 26.2.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
librenms/librenmsPackagist
>= 24.10.0, < 26.2.026.2.0

Affected products

3
  • Librenms/Librenms2 versions
    cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*range: >=24.10.0,<26.2.0
    • (no CPE)range: >= 24.10.0, < 26.2.0
  • ghsa-coords
    Range: >= 24.10.0, < 26.2.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.