CVE-2026-84193EPSS p26.2%
CVE-2026-84193CVE-2026-84193
Description
LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or network access to enroll a rogue SNMP device can inject malicious JavaScript that executes when admins view affected routing and device pages, enabling credential theft and CSRF token exfiltration.
Scoring
| EPSS | 0.35% probability of exploitation · percentile 26.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-08 |