CRITICAL🇵🇱 Wersja polska

CVE-2026-26988

CVSS 9.3v4.0pub. 2026-02-20

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the address parameter is split into an address and a prefix, and the prefix portion is directly concatenated into the SQL query string without validation. This allows an attacker to inject arbitrary SQL commands, potentially leading to unauthorized data access or database manipulation. This issue has been fixed in version 26.2.0.

🤖 AI Analysis
How it works

The application does not properly sanitize or parameterize user input data when processing IPv6 address searches. The address parameter is split into an address part and prefix, and the fragment with the prefix is directly concatenated into the SQL query string without any validation. An attacker can supply a properly crafted string in place of the IPv6 prefix, thereby injecting their own SQL commands into the query executed by the database.

Impact

An attacker can gain unauthorized access to data stored in the database or manipulate it, including reading sensitive configuration information and monitored network infrastructure data.

Mitigation & patch

LibreNMS should be updated to version 26.2.0, in which the vulnerability has been fixed. Patch details are available in the vendor's GitHub repository (commit 15429580baba03ed1dd377bada1bde4b7a1175a1).

Who is affected

LibreNMS in versions 25.12.0 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Librenms

    APP
    Librenms
    < 26.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-51092CRITICAL9.1PL ✓same product

LibreNMS — zdalne wykonanie kodu przez OS command injection (RCE)

CVE-2022-4070CRITICAL9.8PL ✓same product

LibreNMS — niewystarczające wygasanie sesji użytkownika (CWE-613)

CVE-2022-29712CRITICAL9.8PL ✓same product

LibreNMS — wielokrotny command injection w parametrach serwisowych

CVE-2021-44278CRITICAL9.8PL ✓same product

Path Traversal w LibreNMS – dostęp do arbitralnych plików

CVE-2019-10665CRITICAL9.8PL ✓same product

LibreNMS — wstrzyknięcie składni RRDtool przez parametry wykresów