SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84193

MEDIUM · CVSS 5.8 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

LibreNMS versions up to 26.2.0 are vulnerable to a stored cross-site scripting flaw in legacy PHP template pages that improperly handle unescaped SNMP-sourced data. This vulnerability allows attackers with device management or network access to inject malicious JavaScript, potentially leading to credential theft and CSRF token exfiltration when administrators view affected pages. Organizations using LibreNMS should prioritize patching this vulnerability to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84193
Severity
MEDIUM
CVSS
5.8
EPSS
0.27%
Java

Original NVD Description

LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.