Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84189

HIGH NVD
CVSS Score 8.1
Severity HIGH
Published Sep 01, 2026
Vendor unknown

Description

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0.

References