PatchSiren

PatchSiren cyber security CVE debrief

CVE-2020-15874 LibreNMS CVE debrief

CVE-2020-15874 is an authenticated command injection vulnerability in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through the /graph.php API endpoint. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This type of vulnerability can allow attackers to gain unauthorized access to sensitive data or disrupt service. Affected systems should be patched or mitigated as soon as possible. Evidence is limited; primary official records indicate a command injection vulnerability in LibreNMS 1.65. Verify affected scope through inventory checks and vendor remediation status. Defensive verification tasks include reviewing system logs for suspicious activity and ensuring that all instances of LibreNMS 1.65 are identified and patched. Additional evidence gathering may be required to confirm the extent of potential exposure. The CVE record was published on 2026-08-26T17:16:44.097Z and has not been modified since then. AI-assisted PatchSiren debrief based on the supplied source corpus.

Vendor
LibreNMS
Product
LibreNMS 1.65
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-01
Advisory published
2026-08-26
Advisory updated
2026-09-01

Who should care

Administrators and users of LibreNMS 1.65, security teams monitoring for potential command injection attacks, and organizations relying on LibreNMS for network management should be aware of this vulnerability. They should verify their systems for exposure, apply patches or mitigations, and monitor for suspicious activity. Additionally, security teams should review their incident response plans to ensure they are prepared to respond to potential exploitation attempts.

Technical summary

CVE-2020-15874 is an authenticated command injection vulnerability in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through the /graph.php API endpoint. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This type of vulnerability can allow attackers to gain unauthorized access to sensitive data or disrupt service. Affected systems should be patched or mitigated as soon as possible.

Defensive priority

Authenticated attackers with normal privileges can execute arbitrary shell commands via the /graph.php API endpoint in LibreNMS 1.65, posing a high risk with a CVSS score of 8.8.

Recommended defensive actions

  • Verify and apply vendor patches or updates for LibreNMS 1.65
  • Restrict access to the /graph.php API endpoint
  • Monitor for suspicious activity and implement compensating controls
  • Perform inventory checks to identify potentially affected systems
  • Review system logs for signs of exploitation
  • Implement additional security measures such as IP blocking or rate limiting
  • Conduct regular vulnerability assessments to identify potential weaknesses

Evidence notes

Evidence is limited; primary official records indicate a command injection vulnerability in LibreNMS 1.65. Verify affected scope through inventory checks and vendor remediation status. Defensive verification tasks include reviewing system logs for suspicious activity and ensuring that all instances of LibreNMS 1.65 are identified and patched. Additional evidence gathering may be required to confirm the extent of potential exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2020-15874 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2020-15874

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2020-15874 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2020-15874

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.