PatchSiren

LibreNMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH LibreNMS CVE published 2026-08-26

CVE-2020-15874

CVE-2020-15874 is an authenticated command injection vulnerability in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through the /graph.php API endpoint. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This type of vulnerability can allow attackers to gain unauthorized access to sensitive data or disrupt service. Aff [truncated]