Medium severity4.8NVD Advisory· Published Sep 1, 2026
CVE-2026-84188
CVE-2026-84188
Description
LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. The issue is fixed in version 26.7.0.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.