PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84188 librenms CVE debrief

LibreNMS versions less than or equal to 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr settings. An administrator can exploit this by storing a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution. The issue is fixed in version 26.7.0, and defenders should assess exposure and prioritize patching or mitigation to prevent exploitation and impact on system availability and user sessions.

Vendor
librenms
Product
Unknown
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-01
Original CVE updated
2026-10-08
Advisory published
2026-09-01
Advisory updated
2026-10-08

Who should care

Defenders responsible for LibreNMS installations, especially those with administrator access to graph_descr settings, should assess exposure and prioritize patching or mitigation to prevent exploitation and impact on system availability and user sessions. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

This stored XSS vulnerability in LibreNMS can be exploited by an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution and impact on system availability and user sessions.

  • Potential for malicious HTML payload execution in user browsers
  • Possible impact on system availability and user sessions
  • Need for patching or mitigation to prevent exploitation
  • Importance of monitoring for suspicious activity

Technical summary

The vulnerability exists in the graph_descr settings of LibreNMS versions less than or equal to 26.4.0, allowing an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type. This stored XSS vulnerability can be exploited by an administrator to store a malicious HTML payload that executes in the browser of any authenticated user who views the affected graph type, potentially leading to malicious payload execution and impact on system availability and user sessions.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability, especially in environments where administrators have access to graph_descr settings.

Recommended defensive actions

  • Patch or upgrade to version 26.7.0 or later
  • Restrict access to graph_descr settings to prevent exploitation
  • Monitor for suspicious activity on affected systems
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed version. The vulnerability exists in the graph_descr settings of LibreNMS versions less than or equal to 26.4.0. The issue is fixed in version 26.7.0. Defenders should verify the affected scope and severity based on the official advisory or CVE record.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84188 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84188

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84188 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84188

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • librenms before 26.7.0 Stored XSS via graph_descr settings

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/84xxx/CVE-2026-84188.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/librenms-before-26.7.0-stored-xss-via-graph-descr-settings

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.