PatchSiren cyber security CVE debrief
CVE-2026-84188 librenms CVE debrief
LibreNMS versions less than or equal to 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr settings. An administrator can exploit this by storing a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution. The issue is fixed in version 26.7.0, and defenders should assess exposure and prioritize patching or mitigation to prevent exploitation and impact on system availability and user sessions.
- Vendor
- librenms
- Product
- Unknown
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for LibreNMS installations, especially those with administrator access to graph_descr settings, should assess exposure and prioritize patching or mitigation to prevent exploitation and impact on system availability and user sessions. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
This stored XSS vulnerability in LibreNMS can be exploited by an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution and impact on system availability and user sessions.
- Potential for malicious HTML payload execution in user browsers
- Possible impact on system availability and user sessions
- Need for patching or mitigation to prevent exploitation
- Importance of monitoring for suspicious activity
Technical summary
The vulnerability exists in the graph_descr settings of LibreNMS versions less than or equal to 26.4.0, allowing an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. This stored XSS vulnerability can be exploited by an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution and impact on system availability and user sessions.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in environments where administrators have access to graph_descr settings.
Recommended defensive actions
- Patch or upgrade to version 26.7.0 or later
- Restrict access to graph_descr settings to prevent exploitation
- Monitor for suspicious activity on affected systems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The vulnerability exists in the graph_descr settings of LibreNMS versions less than or equal to 26.4.0. The issue is fixed in version 26.7.0. Defenders should verify the affected scope and severity based on the official advisory or CVE record.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84188 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84188
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84188 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84188
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
librenms before 26.7.0 Stored XSS via graph_descr settings
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/84xxx/CVE-2026-84188.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-graph-descr-settings
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.