PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108715 librenms CVE debrief

LibreNMS through 26.9.1.1 contains an authorization bypass vulnerability in Smokeping Graph auth.inc.php, allowing restricted users on a probe device to request smokeping_in or smokeping_out graphs with arbitrary device ids, thereby viewing latency data and enumerating device names. This issue arises from the flawed logic that checks the src probe device instead of the rendered target device, potentially exposing sensitive information and device configurations to unauthorized users. LibreNMS users and administrators should assess their exposure to this vulnerability, verify user permissions, and monitor for suspicious graph requests to mitigate potential risks.

Vendor
librenms
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

LibreNMS users and administrators should assess exposure and verify user permissions to prevent unauthorized access through the Smokeping Graph feature. This includes reviewing current user permissions, monitoring for suspicious graph requests, and ensuring that only authorized users have access to latency data and device information. Additionally, security teams and vulnerability management teams should prioritize patching or mitigating this vulnerability

Why it matters

LibreNMS users and administrators should assess exposure of Smokeping Graph feature, verify user permissions, and monitor for suspicious graph requests to prevent unauthorized access.

  • View latency data for arbitrary device ids
  • Enumerate device names through smokeping_in or smokeping_out graphs

Technical summary

The vulnerability exists in includes/html/graphs/smokeping/auth.inc.php of LibreNMS through 26.9.1.1. The Smokeping Graph feature improperly checks the src probe device instead of the rendered target device, leading to an authorization bypass. This allows restricted users permitted on a probe device to request smokeping_in or smokeping_out graphs with arbitrary device ids, potentially exposing latency data and enabling device name enumeration. The issue highlights the need for stricter access controls and monitoring of graph requests.

Defensive priority

Assess exposure of Smokeping Graph feature, verify user permissions, and monitor for suspicious graph requests.

Recommended defensive actions

  • Assess exposure of Smokeping Graph feature
  • Verify user permissions
  • Monitor for suspicious graph requests
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Plan vendor-supported updates or mitigations

Evidence notes

The CVE Program record and NIST NVD detail page provide information on the authorization bypass vulnerability in LibreNMS through 26.9.1.1. The vulnerability exists in the Smokeping Graph feature, specifically in the auth.inc.php file. The official CVE record and source-specific vulnerability assessment from NIST NVD provide details on the vulnerability, including its potential impact and affected versions. However, the exact scope of affected deployments and specific exploitation attempts remain unknown. Defenders should verify user

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108715 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108715

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108715 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108715

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • LibreNMS through 26.9.1.1 Authorization Bypass via Smokeping Graph auth.inc.php

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108715.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind/librenms-smokeping-graph-src-device-auth-confusion

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/librenms/librenms/blob/26.9.1.1/includes/html/graphs/smokeping/auth.inc.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/librenms/librenms/blob/26.9.1.1/LibreNMS/Util/Graph.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/librenms/librenms

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/librenms-through-26.9.1.1-authorization-bypass-via-smokeping-graph-auth-inc-php

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.